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EXPLANATORY MEMORANDUM 


1. CONTEXT OF THE PROPOSAL 
• Reasons for and objectives of the proposal 

EURODAC was established by Regulation (EC) No 2725/2000 concerning the establishment 
of "Eurodac" for the comparison of fingerprints for the effective application of the Dublin 
Convention 1 . A fïrst recast proposal for the amendment of the EURODAC Regulation was 
adopted by the Council and the European Parliament in June 2013 2 , which enhanced the 
functioning of EURODAC and laid down conditions for law enforcement access to it under 
strict conditions for the prevention, detection and investigation of serious crimes and terrorist 
offences. 

Since it was established, EURODAC has sufficiently served the purpose of providing 
fingerprint evidence to assist determine the Member State responsible for examining an 
asylum application made in the EU. lts primary objective has always been to serve the 
implementation of Regulation (EU) No. 604/2013 (hereafter "the Dublin Regulation") and 
together these two instruments make up what is commonly referred to as the 'Dublin system’. 

When the migration and refugee crisis escalated in 2015, some Member States became 
overwhelmed with fingerprinting all those who arrived irregularly to the EU at the external 
borders, and who further transited through the EU en route to their preferred destination. As 
such, some Member States failed to meet their obligations to take fingerprints under the 
current EURODAC Regulation. The Communication of the Commission of 13 May 2015, 
titled "A European Agenda on Migration" 4 noted that "Member States must also implement 
fully the rules on taking migrants' fingerprints at the borders". This prompted the 
Commission to bring forward guidance to facilitate systematic fingerprinting, in full respect 
of fundamental rights, backed up by practical cooperation and exchange of best practices in 
May 2015.^ In addition to this the Commission also considered the use of other biometric 
identifiers to be used for EURODAC, such as facial recognition and the collection of digital 
photos to counter challenges faced by some Member States to take fingerprints for the 
purposes of EURODAC. 

During the same period, those Member States that are not situated at the extemal borders 
began to see an increasing need to be able to store and compare information on irregular 
migrants that were found illegally staying on their territory, particularly where they did not 
seek asylum. As a consequence, thousands of migrants remain invisible in Europe, including 
thousands of unaccompanied minors, a situation that facilitates unauthorised secondary and 
subsequent movements and illegal stay with in the EU. It became clear that significant steps 
had to be taken to tackle irregular migration that occurred within the EU as well as to the EU. 

The Commission's proposal establishing an Entry/Exit System to register entry and exit data 
of third country nationals Crossing the extemal borders of the EU where a short-stay visa has 
been obtained for entry to the EU, will allow Member States to detect third-country nationals 
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who have been staying illegally although they have entered the EU legally. 6 However no such 
System exists for identifying illegally staying third-country nationals who enter the EU 
irregularly at the external borders and the current EURODAC System - the ideal database that 
could host this infonnation - is limited to identifying whether an asylum application has been 
made in more than one Member State in the EU. 

On 6 April 2016, in its Communication "Towards a reform of the Common European Asylum 
System and enhancing legal avenues to Europe " 7 the Commission considered it a priority to 
bring forward a reform of the Dublin Regulation and establish a sustainable and fair system 
for determining the Member State responsible for asylum seekers ensuring a high degree of 
solidarity and a fair sharing of responsibility between Member States by proposing a 
corrective allocation mechanism. As part of this the Commission considered that EURODAC 
should be reinforced to reflect changes to the Dublin mechanism and to make sure that it 
continues to provide the fingcrprint evidence it needs to function. It was also considered the 
EURODAC could contribute to the (Ight against irregular migration by storing fingcrprint 
data under all categories and allowing comparisons to be made with all stored data for that 
purpose. 

Therefore, this proposal amends the current EURODAC Regulation (EU) No. 603/2013, and 
extends its scope for the purposes of identifying illegally staying third-country nationals and 
those who have entered the European Union irregularly at the external borders, with a view to 
using this infonnation to assist a Member State to re-document a third-country national for 
return purposes. 

Facilitating the idcnti fication of illegally staying third-country nationals or stateless persons 
through the use of biometrics would contribute to improve the effectiveness of the EU return 
policy, notably in relation to irregular migrants who use deceptive means to avoid their 
Identification and to frustrate re-documentation. The availability of data and infonnation on 
third-country nationals without any indcntification or lawful reason for being in the EU who 
are fingcrprintcd in another Member State would accelerate the procedures for the 
Identification and re-documentation of illegally staying third-county nationals apprehended 
and fingcrprintcd in another Member State, hence contributing to reduce the length of the 
necessary return and readmission procedures, including the period during which irregular 
migrants may be kept in administrative detention awaiting removal, and combat identity 
firaud. It would allow identifying country of transit of irregular migrants, hence facilitating 
their readmission in those countries. Furthermore, by providing infonnation on the 
movements of irregular migrants within the EU, it would allow national authorities to carry 
out a more accurate individual assessment of the situation of irregular migrants, for instance 
on the risk that they may abscond, while undertaking return and readmission procedures. 

A record number of refugee and migrant children arrived in Europe in 2015 and Member 
States have struggled to get accurate numbers for unaccompanied and separated children, as 
formal registration procedures in some Member States do not always allow for their 
Identification when they cross borders. The ongoing migration and refugee crisis has raised 
profound questions about how to safeguard and protect unaccompanied children by Members 
of the European Parliament, non-governmental organisations, international organisations and 
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Member States. Child protection and missing children from a third-country in particular has 
become an additional concern of the ensuing crisis within the EU. 8 

Historically, EURODAC has always collected fingerprints of minors from the age of 14 and 
over, which can allow identifïcation of an unaccompanied minor once an asylum application 
has been made within the EU. However, given the apparent increase in the smuggling of 
minors below this age to and within the EU there appears to be a stronger need to collect 
biometrics for the purposes of EURODAC from a lower age to help with the identification of 
such persons and to see whether that information can also assist to establish family links or 
li nk s with a guardian in another Member State. 

Many Member States collect biometrics from minors at a younger age than 14 years for visas, 
passports, biometric residence pennits and general immigration control. Thus it is also 
proposed that the taking of fingerprints of minors for EURODAC should be changed to six 
years old - the age at which research shows that fingerprint recognition of children can be 
achieved with a satisfactory level of accuracy. 

It will also be necessary to store information on illegally staying third-country nationals and 
those apprehended entering the EU irregularly at the external border for longer than what is 
currently permitted. A storage period of 18 months is the maximum permitted under the 
current Regulation for those apprehended at the external border and no data is retained for 
those found illegally staying in a Member State. This is because the current EURODAC 
Regulation is not concerned with storing infonnation on irregular migrants for longer than 
what it necessary to establish the first country of entry under the Dublin Regulation if an 
asylum application had been made in a second Member State. Given the extension of the 
scope of EURODAC for wider migration purposes, it is necessary to retain this data for a 
longer period so that secondary movements can be adequately monitored within the EU, 
particularly where an irregular migrant makes all efforts to remain undetected. A period of 
five years is deemed to be adequate for these purposes, bringing the data retention period in 
line with other EU databases in the Justice and Home Affairs (JHA) area and the period for 
which an entry ban can be imposed on an irregular migrant under the Return Directive. 9 

This proposal also allows for information on the identity of an irregular migrant to be shared 
with a third-country where it is necessary to share that information for return purposes only. 
The readmission and re-documentation of irregular third-country nationals to their country of 
origin entails sharing infonnation on that individual with the authorities of that country when 
a travel document needs to be secured. Thus, this proposal allows data to be shared on that 
basis and in line with data protection rules. A strict prohibition is set out for sharing any 
infonnation on the fact that an asylum application has been made within the EU, which could 
jeopardise a rejected asylum seeker’s safety and lead to a violation of his or her fundamental 
rights. 

It is also proposed that an additional biometric - a facial image - will also be collected by 
Member States and stored in the Central System as well as other personal data to reduce the 
need for additional communication infrastructure between Member States to share 
infonnation on inegular migrants that have not claimed asylum. The collection of facial 
images will be the pre-cursor to introducing facial recognition software in the future and will 
bring EURODAC in line with the other Systems such as the Entry/Exit System. Eu-LISA 
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should first conduct a study on facial recognition software that evaluates its accuracy and 
reliability prior to this software being added to the Central System. 

The Commission’s Communication on Stronger and Smarter Information Systems for Borders 
and Security 10 highlights the need to improve the interoperability of information Systems as a 
long-tenn objective, as also identified by the European Council and the Council. The 
Communication proposes to set up an Expert Group on Information Systems and 
Interoperability to address the legal and technical feasibility of achieving interoperability of 
the information Systems on borders and security. The present proposal is in line with the 
objectives out in the Communication as it establishes EURODAC in a way that allows for 
future interoperability with other information Systems, where necessary and proportionate. To 
that end, and with the support of the Expert Group on Information Systems and 
Interoperability, the Commission will assess the necessity and proportionality of establishing 
interoperability with the Schengen Information Systems (SIS) and the Visa Information 
Systems (VIS). In that context, and in line with the Communication, the Commission will also 
examine if there is a need to revise the legal framework for law enforcement access to 
EURODAC. 

This proposal continues to allow law enforcement access to the Central System and will now 
permit law enforcement authorities and EUROPOL to have access to all the stored 
infonnation in the System and to conduct searches based on a facial image in the future. 

• Consistency with other Union policies 

This proposal is closely linked and complements other Union policies, namely: 

(a) The Common European Asylum System by ensuring the effective implementation 
of the Dublin Regulation by using fingerprint evidence to assist to determine the 
Member State responsible for examining an asylum application. 

(b) An effective EU return policy so as to contribute to and enhance the EU System to 
return irregular migrants. This is essential for maintaining public trust in the EU's 
asylum system and support for helping persons in need of international protection. 
Increasing the rate of return of irregular migrants needs to go hand in hand with the 
EU's renewed efforts to protect those in need. 

(c) Internal security as was underlined in the European Agenda on Security 11 , to 
prevent, detect, investigate and prosecute serious crimes and terrorism offences by 
enabling law enforcement authorities and Europol to process personal data of persons 
suspected to be involved in acts of terrorism or serious crimes. 

(d) European Border and Coast Guard Teams as regards the possibility to take and 
transmit fingerprint and facial image data of asylum applicants and irregular migrants 
to EURODAC on behalf of a Member State for the effective management of external 
border control. 

(e) Data Protection insofar as this proposal must ensure the protection of fundamental 
rights to respect for the private life of individuals whose personal data are processed 
in EURODAC. 
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2. LEGAL BASIS, SUBSIDIARITY AND PROPORTIONALITY 

• Legal basis 

The present recast proposal uses Article 78(2)(e) of the Treaty on the Functioning of the 
European Union (TFEU) as legal base conceming criteria and mechanisms for detennining 
which Member State is responsible for considering an application for asylum or subsidiary 
protection, which is the TFEU Article corresponding to the legal base of the original proposal 
(Article 63(l)(a) of the Treaty establishing the European Community). In addition, it uses 
Article 79(2)(c) as the legal base concerning the elements of indentifying an irregular third- 
country national or stateless person as regards illegal immigration and unauthorised residence, 
including removal and repatriation of persons residing without authorisation, Article 87(2)(a) 
as the legal base conceming the elements related to the collation, storage, processing, analysis 
and exchange of relevant infonnation for law enforcement purposes; and Article 88(2)(a) as 
the legal base concerning Europol’s field of action and tasks including the collection, storage, 
processing, analysis and exchange of infonnation. 

• Variable Geometry 

The United Kingdom and Ireland are bound by Regulation (EU) No. 603/2013 following their 
notification of their wish to take part in the adoption and application of that Regulation based 
on the above-mentioned Protocol. 

In accordance with Protocol 21 on the position of the United Kingdom and Ireland, those 
Member States may decide to take part in the adoption of this proposal. They also have this 
option after adoption of the proposal. 

Under the Protocol on the position of Denmark, annexed to the TEU and the TFEU, Denmark 
does not take part in the adoption by the Council of the measures pursuant to Title V of the 
TFEU (with the exception of "measures detennining the third countries whose nationals must 
be in possession of a visa when Crossing the extemal borders of the Member States, or 
measures relating to a uniform format for visas"). Therefore, Denmark does not take part in 
the adoption of this Regulation and is not bound by it nor subject to its application. However, 
given that Denmark applies the current Eurodac Regulation, following an international 
agreement that it concluded with the EU in 2006, it shall, in accordance with Article 3 of 
that agreement, notify the Commission of its decision whether or not to implement the content 
of the amended Regulation. 

• Impact of the proposal on non-EU Member States associated to the Dublin 
system 

In parallel to the association of several non-EU Member States to the Schengen acquis, the 
Community concluded, or is in the process of doing so, several agreements associating these 
countries also to the Dublin/EURODAC acquis: 

- the agreement associating Iceland and Norway, concluded in 2001 ; 

- the agreement associating Switzerland, concluded on 28 February 2008 14 ; 


Agreement between the European Community and the Kingdom of Denmark on the criteria and 
mechanisms for establishing the State responsible for examining a request for asylum lodged in 
Denmark or any other Member State of the European Union and “Eurodac” for the comparison of 
fmgerprints for the effective application of the Dublin Convention (OJ L 66, 8.3.2006). 

Agreement between the European Community and the Republic of Iceland and the Kingdom of Norway 
concerning the criteria and mechanisms for establishing the State responsible for examining a request 
for asylum lodged in a Member State or in Iceland or Norway (OJ L 93, 3.4.2001, p. 40). 
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- the protocol associating Liechtenstein, concluded on 18 June 2011 15 . 

In order to create rights and obligations between Denmark - which as explained above has 
been associated to the Dublin/EURODAC acquis via an international agreement - and the 
associated countries mentioned above, two other Instruments have been concluded between 
the Community and the associated countries. 16 

In accordance with the three above-cited agreements, the associated countries shall accept the 
Dublin/EURODAC acquis and its development without exception. They do not take part in 
the adoption of any acts amending or building upon the Dublin acquis (including therefore 
this proposal) but have to notify to the Commission with in a given time-frame of their 
decision whether or not to accept the content of that act, once approved by the Council and 
the European Parliament. In case Norway, Iceland, Switzerland or Liechtenstein do not accept 
an act amending or building upon the Dublin/EURODAC acquis, the "guillotine" clause is 
applied and the respective agreements will be terminated, unless the Joint/Mixed Committee 
established by the agreements decides otherwise by unanimity. 

The scope of the above-cited association agreements with Iceland, Norway, Switzerland and 
Liechtenstein as well as the parallel agreement with Denmark does not cover law enforcement 
access to EURODAC. Consequently, once this Recast Regulation is adopted it will be 
necessary to ensure that complementary agreements with those Associated States that wish to 
participate have been signed and concluded. 

The current proposal, stipulates that the comparison of fingerprint data using EURODAC may 
only be made after national fingerprint databases and the Automated Fingerpimt Databases of 
other Member States under Council Decision 2008/615/JHA (the Prüm Agreements) return 
negative results. This rule means that if any Member State has not implemented the above 
Council Decision and cannot perfonn a Prüm check, it also may not make a EURODAC 
check for law enforcement purposes. Similarly, any associated States that have not 
implemented or do not participate in the Prüm Agreements may not conduct such a 
EURODAC check. 

• Subsidiarity 

The proposed initiative constitutes a further development of the Dublin Regulation and EU 
migration policy and in order to ensure that coinmon rules on for the taking of fingerprints 
and facial image data for irregular third-country nationals for the purposes of EURODAC are 
applied in the same way in all the Member States. It creates an instrument providing to the 
European Union information on how many third country nationals enter the EU irregularly 
and claim asylum, which is indispensable for sustainable and evidence based policy making in 


Agreement between the European Community and the Swiss Confederation concerning the criteria and 
mechanisms for establishing the State responsible for examining a request for asylum lodged in a 
Member State or in Switzerland (OJ L 53, 27.2.2008, p. 5). 

Protocol between the European Community, the Swiss Confederation and the Principality of 
Liechtenstein on the accession of the Principality of Liechtenstein to the Agreement between the 
European Community and the Swiss Confederation concerning the criteria and mechanisms for 
establishing the State responsible for examining a request for asylum lodged in a Member State or in 
Switzerland (OJ L 160 18.6.2011 p. 39) 

Protocol between the European Community, the Swiss Confederation and the Principality of 
Liechtenstein to the Agreement between the European Community and the Swiss Confederation 
concerning the criteria and mechanisms for establishing the State responsible for examining a request 
for asylum lodged in a Member State or in Switzerland (2006/0257 CNS, concluded on 24.10.2008, 
publication in OJ pending) and Protocol to the Agreement between the Community, Republic of Iceland 
and the Kingdom of Norway concerning the criteria and mechanisms for establishing the State 
responsible for examining a request for asylum lodged in a Member State, Iceland and Norway (OJ L 
93,3.4.2001). 
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the field of migration and visa. It also grants access for law enforcement authorities to 
EURODAC, which is a timely, accurate, secure and cost-efficient way to identify irregular 
third-country nationals who are suspects (or victims) of terrorism or of a serious crime. 

This proposal will also assist Member States to identify illegally staying third-country 
nationals and those who have entered the European Union irregularly at the external borders, 
with a view to using this infonnation to assist a Member State to re-document a third-country 
national for return purposes. 

Due to the transnational nature of the problems related to asylum and refugee protection, the 
EU is well placed to propose Solutions in the framework of the Common European Asylum 
System (CEAS) to the issues described above as problems regarding the EURODAC 
Regulation. 

An amendment of the EURODAC Regulation is also required in order to add an additional 
purpose thereto, namely allow access for the purpose to control illegal migration to and 
secondary movements of irregular migrants within the EU. This objective cannot be 
sufficiently achieved by the Member States alone. 

• Proportionality 

Article 5 of the Treaty on the European Union States that action by the Union shall not go 
beyond what is necessary to achieve the objectives of the Treaty. The form chosen for this EU 
action must enable the proposal to achieve its objective and be implemented as effectively as 
possible. 

The proposal which conception is driven by the privacy by design principles is proportionate 
in terms of the right to protection of personal data in that it does not require the collection and 
storage of more data for a longer period than is absolutely necessary to allow the System to 
function and meet its objectives. In addition, all the safeguards and mechanisms required for 
the effective protection of the fundamental rights of travellers particularly the protection of 
their private life and personal data will be foreseen and implemented. 

No further processes or harmonisation will be necessary at EU level to make the System work; 
thus the envisaged measure is proportionate in that it does not go beyond what is necessary in 
terms of action at EU level to meet the defined objectives. 

• Choke of the instrument 

The proposed recast will also take the form of a Regulation. The present proposal will build 
on and enhance an existing centralised System through which Member States cooperate with 
each other, something which requires a common architecture and operating rules. Moreover, 
it lays down rules on access to the System including for the purpose of law enforcement which 
are uniform for all Member States. As a consequence, only a Regulation can be chosen as a 
legal instrument. 

3. CONSULTATIONS WITH INTERESTED PARTIES 

In preparation of this proposal, the Commission has relied upon the discussions that have 
been regularly taking place in the European Council and in the Council of Ministers, as well 
as in the European Parliament on the measures needed to address the migratory crisis and in 
particular on the refonn of the Dublin Regulation, which EURODAC is intrinsically attached 
to. The Commission has also reflected on the needs of Member States that became apparent 
during the refugee and migration crisis. 


EN 


8 


EN 



In particular, the Council Conclusions of the European Council of 25-26 June 2015, called for 
the reinforcement of the management of the Union’s external borders to better contain the 
growing flows of illegal migration. 17 At a further meeting of Heads of State or Government in 
October 2015, the European Council concluded that Member States needed to step up 
implementation of the Return Directive and ensure that all those arriving at the hotspots 
would be identified, registered and fingerprintcd and at the same time ensure relocation and 
returns. In March 2016, the European Council further reiterated that work will also be taken 
forward on the future architecture of the EU's migration policy, including the Dublin 
Regulation. 19 

The Commission has also informally consulted the European Data Protection Advisor on the 
new elements of this proposal that are subject to the new legal framework on Data Protection. 

• Fundamental rights 

The proposed Regulation has an impact on fundamental rights, notably on right to human 
dignity (Article 1 of the Charter of Fundamental Rights of the EU); the prohibition of slavery 
and forced labour (Article 5 of the Charter); right to liberty and security (Article 6 of the 
Charter), respect for private and family life (Article 7 of the Charter), the protection of 
personal data (Article 8 of the Charter), right to asylum (Article 18 of the Charter) and 
protection in the event of removal, expulsion or extradition (Article 19 of the Charter), the 
right to non-discrimination (Article 21 of the Charter), the rights of the child (Article 24 of the 
Charter) and the right to an effective remedy (Article 47 of the Charter). 

The prohibition of slavery and forced labour as well as the right to liberty and security are 
positively affected by the implementation of EURODAC. A better and more accurate 
identification (through the use of biometrics) of third-country nationals Crossing the extemal 
border of the EU supports the detection of identity firaud, human being trafficking 
(particularly in the case of minors) and cross border criminality and thus contributes to the 
flght against trafficking and smuggling in human beings. It also contributes to improving the 
security of the citizens anyone present in the EU area on the EU territory. 

The proposal also positively contributes to the protection of the rights of the child and to the 
respect of the right to respect for family life. Many applicants for international protection and 
third-country nationals arriving irregularly to the European Union travel with families and in 
many cases very young children. Being able to identify these children with the help of 
fingerprints and facial images will help identify children in cases where they are separated 
from their families by allowing a Member State to follow up a line of inquiry where a 
fingerprint match indicates that they were present in another Member State. It would also 
strengthen the protection of unaccompanied minors who do not always formally seek 
international protection and who abscond from care institutions or child social services under 
which their care has been assigned. 

The obligation to take fingerprints shall be implemented in full respect of the right to human 
dignity and of the rights of the child. The proposal reaffirms the obligation upon Member 
States to ensure that the procedure for taking fingerprints and a facial image shall be 
determined and applied in accordance with the national practice of the Member State 
concemed and in accordance with the safeguards laid down in the Charter of Fundamental 
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Rights of the European Union, in the Convention for the Protection of Human Rights and 
Fundamental Freedoms and in the United Nations Convention on the Rights of the Child. 
Penalties attached to the failure to comply with the obligation to comply with the 
fingerprinting process shall be in accordance with the principle of proportionality. In 
particular, the proposal explicitly States that detention should only be used in this context as a 
means of last resort if necessary to detennine or verify a third-country national's identity. As 
regards children, the taking of lingcrprints from minors, particularly young children, should 
be carried out in a child-sensitive and child-friendly manner. Relevant provisions also ensure 
that a child is not subject to any administrative sanctions where there is a justified reason for 
not submitting their lingcrprints or a facial image and that the authorities of a Member State 
must ensure that where they suspect that there may be child protection issues following a 
refusal to submit fingerprints or where a child may have damaged fingertips or hands, they 
should refer the child to the national child protection authorities. 

The implementation of the proposal shall be without prejudice to the rights of applicant for 
and beneficiaries of international protection, in particular as regards the prohibition in the 
event of removal, expulsion and extradition, including in the context of transfers of personal 
data to third countries. 

As stipulated by Article 52(1) of the Charter, any limitation to the right to the protection of 
personal data must be appropriate for attaining the objective pursued and not going beyond 
what is necessary to achieve it. Article 8(2) of the European Convention of Human Rights 
also recognises that interference by a public authority with a person’s right to privacy may be 
justified as necessary in the interest of national security, public safety or the prevention of 
crime, as it is the case in the current proposal. The proposal provides for access to 
EURODAC for the prevention, detection or investigation of terrorist offences or other serious 
criminal offences for the purposes of identification of third country nationals Crossing the 
external borders and for the purpose of accessing data on their travel history. Safeguards as 
regards personal data also include the right of access to or the right of correction or deletion 
of data. The limitation of the retention period of data referred to above in chapter 1 of this 
explanatory memorandum also contributes to the respect for personal data as a fundamental 
right. 

The proposal provides for access to EURODAC for the prevention, detection or investigation 
of terrorist offences or other serious criminal offences for the purposes of identification of 
third country nationals Crossing the extemal borders and for the purpose of accessing data on 
their movements within the EU. Moreover, designated law enforcement authorities may only 
request access to EURODAC data if there are reasonable grounds to consider that such access 
will substantially contribute to the prevention, detection or investigation of the criminal 
offence in question. Such requests are verified by a designated law enforcement authority in 
order to check whether the strict conditions for requesting access to the EES for law 
enforcement purposes are fulfilled. 

Furthermore, the proposal also lays down strict data security measures to ensure the security 
of personal data processed and establishes supervision of the processing activities by 
independent public data protection authorities and documentation of all searches conducted. 
The proposal also States that the processing of all personal data carried out by law 
enforcement authorities in EURODAC once they have been extracted is subject to the new 
data protection Directive for the processing of personal data for the prevention, investigation, 
detection or prosecution of criminal offences or the execution of criminal penalties that 
repeals Council Framework Decision 2008/977/JHA. The proposal establishes strict access 
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rules to EURODAC and the necessary safeguards. It also foresees the individuals’ rights of 
access, correction, deletion and redresses in particular the right to a judicial remedy and the 
supervision of processing operations by public independent authorities. Therefore, the 
proposal fully complies with the Charter of Fundamental Rights of the European Union, in 
particular as regards the right to the protection of personal data, and is also in line with Article 
16 TFEU which guarantees everyone the right to protection of personal data concerning them. 

4. BUDGETARYIMPLICATIONS 

The present proposal entails a technical amendment to the EURODAC central system in order 
to provide for the possibility to carry out comparisons for all three categories of data and for 
storage of all three categories of data. Further functionalities such as the storage of 
biographical data alongside side a facial image will require more amendments to the Central 
System 

The financial statement attached to this proposal reflects this change. 

The cost estimate of 29.872 million EUR includes costs for the technical upgrade and 
increased storage and throughput of the Central System. It also consists of IT-related services, 
software and hardware and would cover the upgrade and customisation to allow searches for 
all categories of data covering both asylum and irregular migration purposes. It also reflects 
the additional staffing costs required by eu-LISA. 

5. OTHER ELEMENTS 

• Detailed explanation of the specific provisions of the proposal 

- Extending the scope of EURODAC for return purposes (Article l(T)(b)): The scope of the 
new EURODAC Regulation has been extended to include the possibility for Member States 
to store and search data belonging to third-country nationals or stateless persons who are not 
applicants for international protection so that they can be identified for return and readmission 
purposes. A new legal base, Article 79(2)(c) has been added for these purposes. Thus 
EURODAC becomes a database for wider immigration purposes and no longer only exists to 
ensure the effective implementation of the Dublin III Regulation, although this function will 
still be an important aspect of it. At present EURODAC only compares fingerprint data taken 
from irregular migrants and applicants for international protection against asylum data 
because it is an asylum database. Comparisons are not made between fingerprint data taken 
from irregular migrants at the extemal borders and fingerprint data taken from third-country 
nationals found illegally staying on the territory of a Member State. 

Extending the scope of EURODAC will allow the competent immigration authorities of a 
Member State to transmit and compare data on those illegally staying third-country nationals 
who do not claim asylum and who may move around the European Union undetected. The 
infonnation obtained in a hit result may then assist competent Member State authorities in 
their task of identifying illegally staying third-country nationals on their territory for return 
purposes. It may also provide precious elements of evidence for re-documentation and 
readmission purposes. 

- Ensuring the primacy of the Dublin procedure (Articles 15(4) and 16 (5)): a provision has 
been included to ensure that where a fingerprint hit indicates that an asylum application has 
been made in the European Union, the Member State that conducted the search should ensure 
that the Dublin procedure is followed as a matter of course and not a return procedure for the 
individual concerned. This is to guarantee that where multiple hits are retrieved from the 
Central System relating to the same individual, the Member State that consulted EURODAC 
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is left in no doubt about the correct procedure to follow and so that no applicant for 
international protection is retumed to their country of origin or to a third-country in breach of 
the principle of non-refoulement. Thus the notion of a “hierarchy of hits” has been introduced 
to allow for this. 

- Obligation to take Fingerprints and facial images (Article 2): the proposal specifies a clear 
obligation for Member States to take and transmit fingerprints and a facial image of all three 
categories of persons and makes sure that Member States impose these obligations on 
applicants of international protection and third-country nationals or stateless persons so that 
they are aware. The obligation to take fingerprints has always existed and was communicated 
to the data-subject via information in the form of a leaflet under Article 29(l)(d) of 
Regulation (EU) No. 603/2013. This Article also permits Member States to introducé 
sanctions, in accordance with their national law, for those individuals who refuse to provide a 
facial imagine or comply with the fingerprinting procedure, following, where relevant, the 

Commission Staff Working Document on the implementation of the Eurodac Regulation as 

20 

that sets out a best practice approach for Member States to follow to obtain fingerprints. 
However, new provisions have been laid down to ensure that the taking of fingerprints and a 
facial image from minors, particularly young children, should be carried out in a child- 
sensitive and child-friendly marnier. These provisions also ensure that a minor is not subject 
to any administrative sanctions if they do not submit their fingerprints or a facial image, 
where there is good reason for not submitting them and that the authorities of a Member State 
must ensure that where they suspect that there may be child protection issues following a 
refusal to submit fingerprints or a facial image or where a child may have damaged fingertips 
or hands, they should refer the child to the national child protection authorities. 

- Storing the personal data of the data-subject (Articles 12, 13 and 14) : EURODAC has 
always functioned with fingerprints only and previously no other personal data of the data- 
subject was stored apart from the gender of the individual. The new proposal now permits the 
storage of personal data of the data-subject such as the name(s), age, date of birth, nationality, 
and identity documents, as well as a facial image. The storage of personal data will allow 
immigration and asylum authorities to easily identify an individual, without the need to 
request this infonnation directly from another Member State. Personal data of the individual 
can be retrieved from the Central System on a hit or no hit basis only. This is to safeguard the 
right of access to this data, thus where there is no fingerprint or facial image match the 
personal data cannot be obtained. 

For the purposes of the Dublin Regulation, new information is required to be updated in 
EURODAC relating to the Member State that becomes responsible for examining an asylum 
application following allocation of an applicant to another Member State. This will then make 
clear which Member State is responsible under the recast Dublin Regulation, if an applicant 
absconds or claims asylum in another Member State following an allocation procedure and a 
fingerprint hit. 

- Biometric identifiers (Articles 2, 15, and 16): The current EURODAC Regulation allows for 
the comparison of fingerprint data only. In 2015, the European Agenda on Migration 
suggested the possibility to add other biometric identifiers to EURODAC in order to mitigate 
some of the challenges Member States were facing with damaged fingertips and non- 
compliance with the fingerprint process. This proposal inserts a requirement for Member 


SWD(2015) 150 fïn a l 

21 

Communication from The Commission to The European Parliament, The Council, The European Economie And 
Social Committee And The Committee Of The Rcgions A European Agenda On Migration, COM(2015) 240 fïnal, 
13.5.2015. pp 13-14. 
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States to take a facial image of the data-subject for transmission to the Central System and 
includes provisions to make a comparison of fingerprint and facial image data together and 
facial images separately under defined conditions. The insertion of facial images into the 
Central System now will prime the System for searches to be made with facial recognition 
software in the future. 

Mernber States will continue to take the fingerprints of all ten fingers as plain and rolled 
impressions and this will now apply to individuals who are found illegally staying in a 
Mernber State because the same set of fingerprints will be needed for all three categories to be 
compared accurately. 

- Comparison and transmission of all categories of all data (Articles 15 and 16): whereas 
under Regulation (EU) No. 603/2013, only two fmgerprint categories were stored and data 
could only be searched against fingerprint data of applicants for international protection, the 
fingerprint and facial image data of all three categories of data will now be stored and 
compared against each other. This will allow the immigration authorities in a Member State to 
ascertain whether an illegally staying third-country national in a Member State has claimed 
asylum, or has entered the EU illegally at the extemal border. In the same vein it will allow a 
Member State to check whether someone apprehended Crossing the external border irregularly 
was ever illegally staying in another Member State. Widening the scope of searches allows a 
pattern of irregular and secondary movements to be followed throughout the European Union, 
and can lead to establishing the identity of the individual concemed in the absence of valid 
identity documents. 

- Lowering the age of taking fingerprints to 6 years old (Articles 10, 13 and 14): the age for 
taking fingerprints has always historically been 14 years of age. The study conducted by the 
Commission's Joint Research Centre, on 'Fingerprint Recognition for childreri 22 indicates that 
fingerprints taken from children age six and above can be used in automated matching 
scenarios such as EURODAC when sufficiënt care is taken to acquire good quality images. 

Indeed many Member States take the fingerprints of children at a lower age than six for 
national purposes, such as issuing a passport or a biometric residence permit. 

Many applicants for international protection and third-country nationals arriving irregularly to 
the European Union travel with families and in many cases very young children. Being able 
to identify these children with the help of fingerprints and facial images will help identify 
children in cases where they are separated from their families by allowing a Member State to 
follow up a line of inquiry where a fingerprint match indicates that they were present in 
another Member State. It would also strengthen the protection of unaccompanied minors who 
do not always formally seek international protection and who abscond from care institutions 
or child social services under which their care has been assigned. Under the current legal and 
technical framework their identity cannot be established. Thus the EURODAC System could 
be used to register children from third-countries where they are found undocumented within 
the EU to help keep track of thern and prevent them from ending up in scenarios of 
exploitation. 

- Data retention (Article 17): the data retention period of applicants for international 
protection remains the same at 10 years. This is to ensure that Member States can track 
secondary movements within the European Union following a grant of international 
protection status where the individual concerned is not authorised to reside in another 
Member State. Given that the recast Dublin Regulation will include in its scope beneficiaries 
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of international protection, this data can now be used to transfer back refugees or persons 
granted subsidiary protection status to the Member State that granted them such protection. 

Fingerprint data for illegally staying third-country nationals who do not claim asylum will be 
retained for five years. This is because EURODAC is no longer a database for asylum 
applicants only and retaining this data for longer is necessary to ensure that illegal 
immigration and secondary movements within and to the EU can be sufficiently monitored. 
This storage period is aligned with the maximum period for placing an entry ban on an 
individual for migration purposes as set out in Article 11 of the Returns Directive 
2008/115/EC, the data retention period for storing information on a visa (Article 23 of the 
Visa Regulation), and the proposed data retention period for storing data in the Entry/Exit 
System (Article 31 of the EES). 

- Advanced data erasure (Article 18): advanced data erasure remains the same for applicants 
for international protection and irregular third-country nationals or stateless persons who are 
granted citizenship. Data belonging to these individuals that is stored in the central system 
will be deleted in advance if citizenship of a Member State is obtained because they no longer 
fall within the scope of EURODAC. 

Data will no longer be deleted in advance for illegally staying third-country nationals or 
stateless persons who were granted a residence document or left the territory of the European 
Union. It is necessary to retain this data in case at some point a residence document, which 
normally confers limited leave, is no longer valid and the individual overstays, or the illegally 
staying third-country national who had returned to a third country may attempt to re-enter the 
EU in an irregular marnier again. 

- Marking of data for illegally staying third-country nationals (Article 19 (4) and (5)): 
Currently under the EURODAC Regulation, the data of illegally staying third-country 
nationals who do not lodge an application for asylum within the European Union is erased in 
advance once a residence document is obtained. The proposal introducés changes to allow for 
this data to be marked instead of erased in advance, so that when a Member State conducts a 
search in EURODAC, which results in a marked hit from the Central system, it can ascertain 
immediately that the illegally staying third-country national has been given a residence 
document by another Member State. It may then be possible, under Article 6(2) of the Return 
Directive to pass back the individual to the Member State that issued the residence document. 

Data for applicants for international protection is blocked for law enforcement purposes after 
three years; however, the data of illegally staying third-country nationals, who do not apply 
for international protection and who have been granted a temporary residence document, will 
not be blocked for law enforcement purposes. This is to ensure that where a residence 
document expires before the five-year data retention period lapses, the data is still searchable. 
Data belonging to asylum applicants will continue to be treated differently in this respect 
because asylum applicants are more likely to obtain a renewal of their residence pennit as a 
beneficiary of international protection or a long-tenn residence pennit. 

- Sharing information obtained from EURODAC with third-countries (Article 38): sharing 
infonnation with a third country, international organisation or private entity is strictly 
prohibited under the current Regulation. Extending the scope of EURODAC to assist a 
Member State to use EURODAC data for identifying and re-documenting an illegally staying 
third-country national for return and readmission purposes will necessarily entail sharing that 
data in some circumstances, with a third country - for the legitimate and sole purposes of 
return. Thus a specific provision to allowing sharing data with third countries for return 
purposes has been included, that sets out very strict conditions under which this data can be 
shared. It also strictly forbids the EURODAC database to be accessed by a third country, 
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which is not a party to the Dublin Regulation, or to allow a Member State to check data on 
behalf of a third country. By adding this provision on sharing data with third countries, 
EURODAC is aligned with other databases such as the VIS and the Entry/Exit System that 
also contain similar provisions for sharing information for return purposes. 

- Access for law enforcement authorities and EUROPOL! Article 20 (3)): minor amendments 
have been made to the provisions for law enforcement access to make sure that all three 
categories of data stored in the Central System can be compared against when a law 
enforcement search is carried out and to allow in the future, a search based on a facial image. 

-Allowing European Border and Coast Guards and EASO Member State experts to take 
fingerprints (Article 10(3) and 13 (7): the proposal pennits, at the discretion of a Member 
State, the European Border [and Coast] Guard Agency and Member State's asylum experts 
that are deployed to a Member State under the auspices of EASO, to take and transmit 
fingerprints to EURODAC on behalf of a Member State. The proposal limits these functions 
to areas where both Agencies' mandates permit them do this (i.e. at the external border for 
those entering illegally and for asylum applicants). 

- Statistics (Article 9): to allow for more transparency of EURODAC data, amendments have 
been made to the type of statistics that are published and the frequency of publication by eu- 
LISA. New provisions have been included to allow for statistical data obtained from 
EURODAC to be shared with the relevant Justice and Home Affairs Agencies for analysis 
and research purposes. Statistics produced by eu-LISA for these purposes should not report 
any names, individual date of births, or any personal data that would individually identify a 
data-subject. Amendments have also been introduced to allow the Commission to request ad- 
hoc statistics from eu-LISA on request. 

- Architecture and operational management of the Central System (Article 4 and 5): changes 
have been made to the communication infrastructure to allow for the Central System to make 
use of the Eurodomain, which will bring significant economies of scale. The operational 
management of DubliNet as an existing separate communication infrastructure for the 
purposes of the Dublin Regulation has also been incorporated under the System architecture 
and will ensure that both its financial and operational management is transferred to eu-LISA, 
who currently is only responsible for its operational management via a separate Memorandum 
of Understanding with the Commission (DG HOME). 

- Providing infonnation on false hits (Article 26(6)): Member States will now be required to 
inform only eu-LISA of the fact that a false hit was received by the Central System and give 
eu-LISA infonnation relating to that hit so that they can unlink the false hit records from the 
database. In the future eu-LISA will compile statistics on the number of reported false hits so 
that the Commission will no longer need to be informed directly of a false hit. 

- Using real personal data for testing (Article 5(1)): When it has come to testing the 
EURODAC Central System, eu-LISA has been restricted to using 'dummy data' for the test 
environment and to test new technologies, which has failed to yield good test results because 
of the data used. The proposal allows for the use of real personal data when testing the Central 
System for diagnostics and repair, as well as the use of new technologies and techniques, 
subject to stringent conditions and on the basis that the data is anonymised for the testing 
purposes and cannot be used for individual identification. 
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* 603/2013 (adapted) 
2016/0132 (COD) 


Proposal for a 

REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL 


on the establishment of 'Eurodac' for the comparison of fingerprints for the effective 
application of [Regulation (EU) No 604/2013 establishing the criteria and mechanisms 
for determining the Member State responsible for examining an application for 
international protection lodged in one of the Member States by a third-country national 
or a stateless person] \E> , for identifying an illegally staying third-country national or 
stateless person O and on requests for the comparison with Eurodac data by Member 
States' law enforcement authorities and Europol for law enforcement purposes* and 


operational management of large - scale IT systems in the area of freedom, security and 

justice (recast) 


THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION, 

Having regard to the Treaty on the Functioning of the European Union, and in particular 
Articles 78 (2)(e), E> 79(2)(c), O 87(2)(a) and 88(2)(a) thereof, 

Having regard to the proposal from the European Commission 

After transmission of the draft legislative act to the national Parliaments, 

Having regard to the opinion of the European Data Protection Supervisor, 

Acting in accordance with the ordinary legislative procedure, 

Whereas: 


i 603/2013 recital 1 (adapted) 

(1) A number of substantive changes are to be made to Council Regulation (EC) 
No 2725/2000 of 11 December 2000 concorning the establishment of'Eurodac' for the 
c omparison of fingerprints for the effective application of the Dublin ConventioB 3 * 
and to Council Rogulation (EC) No 107/2002 of 28 Fobruary 2002 laying down 
cortain — mies —te— implomont — Rogulation (EC) — No 2725/2000 — concorning —tbc 
establishment of "Eurodac" for the comparison of fingerprints for the offoctivo 
application of the Dublin Convontion 34 \E> Regulation (EU) No 603/2013 of the 
European Parliament and of the Council 25 <3 . In the intcrests of clarity, thoso 
E> that <3 Regulation» should be recast. 


OJ L 316. 15.12.2000. p. 1. 

OJL 62. 5.3.2002. p. 1. 

Regulation (EU) No 603/2013 of the European Parliament and of the Council of 26 June 2013 on the 
establishment of 'Eurodac' for the comparison of fingerprints for the effective application of Regulation 


EN 


16 


EN 




* 603/2013 recital 2 _ 

(2) A common policy on asylum, including a Common European Asylum System, is a 
constituent part of the European Union's objective of progressively establishing an 
area of freedom, security and justice open to those who, forced by circumstances, seek 
international protection in the Union. 


^ 603/2013 recital 3 (adapted) 

(3) The Europoan Council of 1 November 2001 adoptod The Haguo Programmo which set 
t bc objcctivcs to bc implcmcntcd in the arca of frccdom, security and justicc in t b# 
poriod 2005 2010. The Europoan Pact on Immigration and Asylum endorsod by the 
E uropcan Council of 15 - 16 Octobcr 2008 callcd for the complction of t b# 
establishment of a Common Europoan Asylum System by crcating a single procedure 
e omprising common guarantccs and a uniform status for rcfugccs and for perso m 
oligiblo for subsidiary protoction. 


^ 603/2013 recital 4 (adapted) 

(4) For the purposes of applying Regulation (EU) No [.../...] of the European Parliament 
and of the Council — 1 of 26 Junc 2013 establishing the criteria and mechanisms for 
determining the Member State resnonsible for examining an application for 
international protection lodged in one of the Member States bv a third-countrv national 
or a stateless person 27 . it is necessary to establish the identity of applicants for 
international protection and of persons apprehended in connection with the unlawful 
Crossing of the external borders of the Union. It is also desirable, in order effectively 
to apply Regulation (EU) No [.../...], and in particular Articles[..] and [..]) thereof, to 
allow each Member State to check whether a third-country national or stateless person 
found illegally staying on its territory has applied for international protection in 
another Member State. 


(EU) No 604/2013 establishing the criteria and mechanisms for determining the Member State 
responsible for examining an application for international protection lodged in one of the Member 
States by a third-country national or a stateless person and on requests for the comparison with Eurodac 
data by Member States' law enforcement authorities and Europol for law enforcement purposes, and 
amending Regulation (EU) No 1077/2011 establishing a European Agency for the operational 
management of large-scale IT systems in the area of freedom, security and justice (OJ L 180, 29.6.2013, 

p. 1). 

Regulation (EU! No 601/2013 of the European Parliament and of the Council of 26 June 2013 

establishing the criteria and mechanisms for determining the Member State responsible for examining 

an annlication for international nrotection lodged in one of the Member States bv a third - countrv 

national or a stateless person (OJ L 180. 29.6.2013. n. 31b 
See oase 31 of this Official Journal. 
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^ 603/2013 recital 5 (adapted) 

■=> new 

(5) Fingerprints ■=> Biometrics O constitute an important element in establishing the exact 
identity of such persons. It is necessary to set up a system for the comparison of their 
fingerprint O and facial image <=■ data. 


* 603/2013 recital 6 
■=> new 

(6) To that end, it is necessary to set up a system known as 'Eurodac', consisting of a 
Central System, which will operate a computerised central database of fingerprint 
O and facial image O data, as well as of the electronic means of transmission between 
the Member States and the Central System, hereinafter the "Communication 
Infrastructure". 


-0- new 

(7) For the purposes of applying and implementing Regulation (EU) No. [.../...] it is also 
necessary to ensure that a separate secure communication infrastructure exists, which 
Member State's competent authorities for asylum can use for the exchange of 
information on applicants for international protection. This secure electronic means of 
transmission shall be known as 'DubliNef and should be managed and operated by eu- 
LISA. 


^ 603/2013 recital 7 (adapted) 

(8) The Haguc Programmc callcd for the improvcmcnt of acccss to cxisting data fi fing 
systcms in the Union. In addition, The Stockholm Programmo callod for woll targotod 
data colloction and a dovolopmont of information exchange and its tools that is drivon 
by law onforcomont noods. 


-0- new 

(9) In 2015, the refugee and migration crisis brought to the fore challenges faced by some 
Member States with taking fingerprints of illegally staying third-country nationals or 
stateless persons who attempted to avoid the procedures for determining the Member 
State responsible for examining an application for international protection. The 
Communication of the Commission of 13 May 2015, titled "A European Agenda on 
Migration" noted that " Member States must also implement fully the rules on taking 
migrants'fingerprints at the borders" and further proposed that "The Commission will 
also explore how more biometric identifiers can be used through the Eurodac system 
(such as using facial recognition techniques through digitalphotos)". 


COM(2015) 240 final, 13.5.2015 
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(10) To assist Member States overcome challenges relating to non-compliance with the 
fingerprinting process, this Regulation also permits the comparison of a facial image 
without fingerprints as a last resort, where it is impossible to take the fingerprints of 
the third-country national or stateless person because his or her fingertips are 
damaged, either intentionally or not, or amputated. Member States should exhaust all 
attempts to ensure that fingerprints can be taken from the data-subject before a 
comparison using a facial image only can be carried out where non-compliance based 
on reasons not relating to the conditions of the individual's fingertips are given. Where 
facial images are used in combination with fingerprint data, it allows for the reduction 
of fingerprints registered while enabling the same result in terms of accuracy of the 
identification. 

(11) The return of third-country nationals who do not have a right to stay in the Union, in 
accordance with fundamental rights as general principles of Union law as well as 
international law, including refugee protection and human rights obligations, and in 
compliance with the provisions of Directive 2008/115/EC" , is an essential part of the 
comprehensive efforts to address migration and, in particular, to reduce and deter 
irregular migration. To increase the effectiveness of the Union system to return 
illegally staying third-country nationals is needed in order to maintain public trust in 
the Union migration and asylum system, and should go hand in hand with the efforts 
to protect those in need of protection. 

(12) National authorities in the Member States experience difficulties in identifying 
illegally staying third-country nationals who use deceptive means to avoid their 
identification and to frustrate the procedures for re-documentation in view of their 
return and readmission. It is therefore essential to ensure that information on third- 
country nationals or stateless persons who are found to be staying illegally in the EU 
are collected and transmitted to Eurodac and are compared also with those collected 
and transmitted for the purpose of establishing the identity of applicants for 
international protection and of third-country nationals apprehended in connection with 
the unlawful Crossing of the extemal borders of the Union, in order to facilitate their 
identification and re-documentation and to ensure their return and readmission, and to 
reduce identity firaud. It should also contribute to reducing the length of the 
administrative procedures necessary for ensuring return and readmission of illegally 
staying third-country nationals, including the period during which they may be kept in 
administrative detention awaiting removal. It should also allow identifying third 
countries of transit, where the illegally staytng third-country national may be 
readmitted. 

(13) In its Conclusions of 8 October 2015 on the future of return policy, the Council 
endorsed the initiative announced by the Commission to explore an extension of the 
scope and purpose of Eurodac to enable the use of data for return purposes 30 . Member 
States should have the necessary tools at their disposal to be able to detect illegal 
migration to and secondary movements of illegally staying third-country nationals in 
the Union. Therefore, the data in Eurodac should be available, subject to the 
conditions set out in this Regulation, for comparison by the designated authorities of 
the Member States. 


Directive of the European Parliament and of the Council of 16 December 2008 on common standards 
and procedures in Member States for returning illegally staying third-country nationals, OJ L 348, 
24,12,2008, p. 98. 

EU Action Plan on return, COM(2015) 453 frnal. 
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(14) The Commission’s Communication on Stronger and Smarter Information Systems for 
Borders and Security highlights the need to improve the interoperability of 
information Systems as a long-term objective, as also identified by the European 
Council and the Council. The Communication proposes to set up an Expert Group on 
Information Systems and Interoperability to address the legal and technical feasibility 
of achieving interoperability of the infonnation Systems for borders and security. This 
group should assess the necessity and proportionality of establishing interoperability 
with the Schengen Infonnation Systems (SIS) and the Visa Information Systems 
(VIS), and examine if there is a need to revise the legal framework for law 
enforcement access to EURODAC. 


* 603/2013 recital 8 _ 

(15) It is essential in the light against terrorist offences and other serious criminal offences 
for the law enforcement authorities to have the fullest and most up-to-date infonnation 
if they are to perform their tasks. The information contained in Eurodac is necessary 
for the purposes of the prevention, detection or investigation of tenorist offences as 
refened to in Council Framework Decision 2002/475/JHA of 13 June 2002 on 
combating tcrroris m ~ or of other serious criminal offences as referred to in Council 
Framework Decision 2002/584/JHA of 13 June 2002 on the European ancst warr ant 
and the surrendcr procedures botweon Membor States 33 . Therefore, the data in Eurodac 
should be available, subject to the conditions set out in this Regulation, for comparison 
by the designated authorities of Member States and the European Police Office 
(Europol). 


* 603/2013 recital 9 _ 

(16) The powers granted to law enforcement authorities to access Eurodac should be 
without prejudice to the right of an applicant for international protection to have his or 
her application processed in due course in accordance with the relevant law. 
Furthermore, any subsequent follow-up after obtaining a 'hit' from Eurodac should 
also be without prejudice to that right. 


^ 603/2013 recital 10 (adapted) 

(17) The Commission outlincs IE> outlined <3 in its Communication to the Council and the 
European Parliament of 24 November 2005 on improved effectiveness, enhanced 
interoperability and synergies among European databases in the area of Justice and 
Home Affairs that authorities responsible for internal security could have access to 
Eurodac in wcll-defined cases, when there is a substantiated suspicion that the 
perpetrator of a terrorist or other serious criminal offence has applied for international 
protection. In that Communication the Commission also found that the proportionality 


COM(2016) 205 final 

Council Framework Decision 2002/475/JHA of 13 June 2002 on combating terrorism i OJ L 164, 
22.6.2002, p. 3). 

Council Framework Decision 2002/584/JHA of 13 June 2002 on the Eurooean arrest warrant and the 
surrender procedures between Member States l OJ L 190, 18.7.2002, p. 1). 
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principle requires that Eurodac be queried for such purposes only if there is an 
overriding public security concern, that is, if the act committed by the criminal or 
terrorist to be identified is so reprehensible that it justifies querying a database that 
registers persons with a clean criminal record, and it concluded that the threshold for 
authorities responsible for internal security to query Eurodac must therefore always be 
significantly higher than the threshold for querying criminal databases. 


* 603/2013 recital 11 _ 

(18) Moreover, Europol plays a key role with respect to cooperation between Member 
States' authorities in the field of cross-border crime investigation in supporting Union- 
wide crime prevention, analyses and investigation. Consequently, Europol should also 
have access to Eurodac within the framework of its tasks and in accordance with 
Council Decision 2009/371/JHA of 6 April 2009 establishing the European Police 
O ffice (Europol) 14 . 


* 603/2013 recital 12 _ 

(19) Requests for comparison of Eurodac data by Europol should be allowed only in 
specific cases, under specific circumstances and under strict conditions. 


* 603/2013 recital 13 
■=> new 

(20) Since Eurodac was originally established to facilitate the application of the Dublin 
Convention, access to Eurodac for the purposes of preventing, detecting or 
investigating terrorist offences or other serious criminal offences constitutes a change 
of the original purpose of Eurodac, which interferes with the fundamental right to 
respect for the private life of individuals whose personal data are processed in 
Eurodac. O In line with the requirements of Article 52(1) of the Charter of 
Fundamental Rights of the European Union, O Aanv such interference must be in 
accordance with the law, which must be formulated with sufficiënt precision to allow 
individuals to adjust their conduct and it must protect individuals against arbitrariness 
and indicate with sufficiënt clarity the scope of discretion conferred on the competent 
authorities and the rnanner of its exercise. Any interference must be necessary m=a 
democratie society to protcct a lcgitimatc and proportionatc ■=> to genuinely meet an 
objective of general O interest and proportionate to the legitimate objective it aims to 
achieve. 


* 603/2013 recital 14 _ 

(21) Even though the original purpose of the establishment of Eurodac did not require the 
facility of requesting comparisons of data with the database on the basis of a latent 
fingerprint, which is the dactyloscopie tracé which may be found at a crime scene, 


Council Decision 2009/371/JHA of 6 April 2009 establishing the European Police Office (Europol) f OJ 
L 121, 15.5.2009, p. 37). 
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such a facility is fundamental in the field of police cooperation. The possibility to 
compare a latent fingerprint with the fingerprint data which is stored in Eurodac in 
cases where there are reasonable grounds for believing that the perpetrator or victim 
may fall under one of the categories covered by this Regulation will provide the 
designated authorities of the Member States with a very valuable tooi in preventing, 
detecting or investigating terrorist offences or other serious criminal offences, when 
for example the only evidence available at a crime scene are latent fingerprints. 


* 603/2013 recital 15 _ 

(22) This Regulation also lays down the conditions under which requests for comparison of 
fingerprint data with Eurodac data for the purposes of preventing, detecting or 
investigating terrorist offences or other serious criminal offences should be allowed 
and the necessary safeguards to ensure the protection of the fundamental right to 
respect for the private life of individuals whose personal data are processed in 
Eurodac. The strictness of those conditions reflects the fact that the Eurodac database 
registers fingerprint data of persons who are not presumed to have committed a 
terrorist offence or other serious criminal offence. 


^ 603/2013 recital 16 (adapted) 

(23) With a view to ensuring equal treatment for all applicants and beneficiaries of 
international protection, as well as in order to ensure consistency with the current 
Union asylum acquis, in particular with Directive 2011/95/EU of the European 
Parliament and of the Council of 13 December 2011 on standards for the aualification 
e f third - countrv nationals or stateless persons as beneficiaries of international 

p rotection. for a uniform status for refuGCCO or for poroono cliuiblc for ouboidia #¥ 
protection, and for the content of the protection uran ted 35 and Regulation (EU) No 
[.../...] 60d/2013 , it is appropriatc to extend the scope of this Regulation in order to 
includo E> includes <3 applicants for subsidiary protection and persons eligible for 
subsidiary protection 1E> in its scope <3 . 


* 603/2013 recital 17 
■=> new 

(24) It is also necessary to require the Member States promptly to take and transmit the 
fingerprint data of every applicant for international protection and of every third- 
country national or stateless person who is apprehended in connection with the 
irregular Crossing of an external border of a Member State O or is found to be staying 
illegally in a Member State <p , if they are at least 44 ■=> six <=■ years of age. 


Directive 2011/95/EU of the European Parliament and of the Council of 13 December 2011 on 
standards for the aualification of third-countrv nationals or stateless persons as beneficiaries of 
international protection. for a uniform status for refueees or for nersons eligible for subsidiary 
protection. and for the content of the protection granted i OJ L 337, 20.12.2011, p. 9). 
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-O- new 

(25) In view of strengthening the protection of unaccompanied minors who have not 
applied for international protection and those children who may become separated 
from their families, it is also necessary to take fingerprints and a facial image for 
storage in the Central System to help establish the identity of a child and assist a 
Member State to tracé any family or links they may have with another Member State. 
Establishing family links is a key element in restoring family unity and must be is 
closely linked to the determination of the best interests of the child and eventually, the 
determination of a durable solution. 

(26) The best interests of the minor should be a primary consideration for Member States 
when applying this Regulation. Where the requesting Member State establishes that 
Eurodac data pertain to a child, these data may only be used for law enforcement 
purposes by the requesting Member State in accordance with that State's laws 
applicable to minors and in accordance with the obligation to give primary 
consideration to the best interests of the child. 


^ 603/2013 recital 18 (adapted) 

■=> new 

(27) It is necessary to lay down precise rules for the transmission of such fingerprint ■=> and 
facial image <=■ data to the Central System, the recording of such fingerprint O and 
facial image <=■ data and of other relevant EH> personal O data in the Central System, 
their storage, their comparison with other fingerprint O and facial image O data, the 
transmission of the results of such comparison and the marking and erasure of the 
recorded data. Such rules may be different for, and should be specifically adapted to, 
the situation of different categories of third-country nationals or stateless persons. 


^ 603/2013 recital 19 (adapted) 

O new 

(28) Member States should ensure the transmission of fingerprint O and facial image O 
data of an appropriate quality for the purpose of comparison by means of the 
computerised fingerprint O and facial <=> recognition system. All authorities with a 
right of access to Eurodac should invest in adequate training and in the necessary 
technological equipment. The authorities with a right of access to Eurodac should 
inform the European Agency for the operational management of large-scale IT 
Systems in the area of freedom, security and justice established by Regulation (EU) 
No 1077/2011 of the European Parliament and of the Council 36 ( the "Agcncy" [S> "eu- 
LISA" <3 ) of specific difficulties encountered with regard to the quality of data, in 
order to resolve them. 


Regulation (EU) No 1077/2011 establishing a European Agencv for the operational management of 
large-scale IT svstems in the area of freedom. securitv and iustice 1 0J L 286, 1.11.2011, p. 1). 
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* 603/2013 recital 20 
■=> new 

(29) The fact that it is temporarily or permanently impossible to take and/or to transmit 
fingerprint O and facial image O data, due to reasons such as insufficiënt quality of 
the data for appropriate comparison, technical problems, reasons linked to the 
protection of health or due to the data subject being unfit or unable to have his or her 
fingerprints O or facial image O taken owing to circumstances beyond his or her 
control, should not adversely affect the examination of or the decision on the 
application for international protection lodged by that person. 


-0- new 


(30) Member States should refer to the Commission’s Staff Working Document on 
Implementation of the Eurodac Regulation as regards the obligation to take 

”3 H 

fingerprints adopted by the Council on 20 July 2015 , which sets out a best practice 
approach to taking fingerprints of irregular third-country nationals. Where a Member 
State's national law allows for the taking of fingerprints by force or coercion as a last 
resort, those measures must fully respect the EU Charter of Fundamental Rights. 
Third-country nationals who are deemed to be vulnerable persons and minors should 
not be coerced into giving their fingerprints or facial image, except in duly justified 
circumstances that are permitted under national law. 


^ 603/2013 recital 21 (adapted) 

O new 

(31) Hits obtained from Eurodac should be verified by a trained fingerprint expert in order 
to ensure the accurate detennination of responsibility under Regulation (EU) No 
[■■■/...]6 04/2013 ■=> ; the exact identification of the third-country national or stateless 
person O and the exact identification of the criminal suspect or victim of crime whose 
data might be stored in Eurodac. O Hits obtained from Eurodac based on facial 
images should also be verified where there is doubt that the result relates to the same 
person. O 


^ 603/2013 recital 22 (adapted) 

O new 

(32) Third-country nationals or stateless persons who have requested international 
protection in one Member State may havo the option of ■=> try to <=■ requcstmg 
international protection in another Member State for many years to come. Therefore, 
the maximum period during which fingerprint O and facial image O data should be 
kept by the Central System should be of considerable length. Given that most third- 
country nationals or stateless persons who have stayed in the Union for several years 
will have obtained a settled status or even citizenship of a Member State after that 


COM(2015) 150 final, 27.5.2015 
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period, a period of ten years should be considered a reasonable period for the storage 
of fingerprint O and facial image <=■ data. 


-0- new 

(33) In view of successfully preventing and monitoring unauthorised movements of third- 
country nationals or stateless persons who have no right to stay in the Union, and of 
taking the necessary measures for successfully enforcing effective return and 
readmission to third countries in accordance with Directive 2008/115/EC 38 and the 
right to protection of personal data, a period of five years should be considered a 
necessary period for the storage of fingerprint and facial data. 


* 603/2013 recital 23 
■=> new 

(34) The storage period should be shorter in certain special situations where there is no 
need to keep fingerprint O and facial O data ■=> and all other personal data O for that 
length of time. Fingerprint ■=> and facial image <=> data ■=> and all other personal data 
belonging to a third-country national <=> should be erased immediately once third- 
country nationals or stateless persons obtain citizenship of a Member State. 


* 603/2013 recital 24 
■=> new 

(35) It is appropriate to store data relating to those data subjects whose fingerprints ■=> and 
facial images <=■ were initially recorded in Eurodac upon lodging their applications for 
international protection and who have been granted international protection in a 
Member State in order to allow data recorded upon lodging an application for 
international protection to be compared against them. 


^ 603/2013 recital 25 (adapted) 

(36) The Agoncy E> eu-LISA <3 has been entrusted with the Commission's tasks relating 
to the operational management of Eurodac in accordance with this Regulation and 
with certain tasks relating to the Communication Infrastructure as from the date on 
which the Agoncy [S> eu-LISA <3 took up its responsibilities on 1 December 2012. 
T he Agency should take up the tasks entrusted to it under this Regulation, and t he 
relevant provisions of Regulation (EU) No 1077/2011 should be amondod accordingly. 
In addition, Europol should have observer status at the meetings of the Management 
Board of the Agoncy E> eu-LISA <3 when a question in relation to the application of 
this Regulation concerning access for consultation of Eurodac by designated 
authorities of Member States and by Europol for the purposes of the prevention, 
detection or investigation of terrorist offences or of other serious criminal offences is 


38 OJ L 348, 24.12.2008, p.98 


EN 


25 


EN 




on the agenda. Europol should be able to appoint a representative to the Eurodac 
Advisory Group of \E> eu-LISA <3 the Agoncy . 


* 603/2013 recital 26 _ 

The Staff Regulations of Officials of the European Elnion (Staff Regulations of Officials) a nd 
the Conditions of Employmcnt of Othcr Scrvants of the Europcan Union ('Conditions of 
Employmenf), laid down in Regulation (EEC, Euratom, ECSC) No 259/68 of the Council^ 
(togcthcr rcfcrrcd to as the 'Staff Regulations’) should apply to all staff working in the Agcn ey 
on matters pertaining to this Regulaties 


i 603/2013 recital 27 (adapted) 

(37) It is necessary to lay down clearly the respective responsibilities of the Commission 
and E> eu-LISA <3 the— Agoncy , in respect of the Central System and the 
Communication Infrastructure, and of the Member States, as regards data processing, 
data security, access to, and correction ot= recorded data. 


* 603/2013 recital 28 _ 

(38) It is necessary to designate the competent authorities of the Member States as well as 
the National Access Point through which the requests for comparison with Eurodac 
data are made and to keep a hst of the operating units within the designated authorities 
that are authorised to request such comparison for the specific purposes of the 
prevention, detection or investigation of terrorist offences or of other serious criminal 
offences. 


* 603/2013 recital 29 _ 

(39) Requests for comparison with data stored in the Central System should be made by the 
operating units within the designated authorities to the National Access Point, through 
the verifying authority* and should be reasoned. The operating units within the 
designated authorities that are authorised to request comparisons with Eurodac data 
should not act as a verifying authority. The verifying authorities should act 
independently of the designated authorities and should be responsible for ensuring, in 
an independent marnier, strict compliance with the conditions for access as established 
in this Regulation. The verifying authorities should then forward the request, without 
forwarding the reasons for it, for comparison through the National Access Point to the 
Central System following vcrification that all conditions for access are fulfilled. In 
exceptional cases of urgency where early access is necessary to respond to a specific 
and actual threat related to terrorist offences or other serious criminal offences, the 
verifying authority should process the request immediately and only carry out the 
verification afterwards. 


OJL 56,1.3.1968, p. 1. 
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* 603/2013 recital 30 _ 

(40) The designated authority and the verifying authority may be part of the same 
organisation, if permitted under national law, but the verifying authority should act 
independently when performing its tasks under this Regulation. 


* 603/2013 recital 31 _ 

(41) For the purposes of protection of personal data, and to exclude systematic comparisons 
which should be forbidden, the processing of Eurodac data should only take place in 
specific cases and when it is necessary for the purposes of preventing, detecting or 
investigating terrorist offences or other serious criminal offences. A specific case 
exists in particular when the request for comparison is connected to a specific and 
concrete situation or to a specific and concrete danger associated with a terrorist 
offence or other serious criminal offence, or to specific persons in respect of whom 
there are serious grounds for believing that they will commit or have committed any 
such offence. A specific case also exists when the request for comparison is connected 
to a person who is the victim of a terrorist offence or other serious criminal offence. 
The designated authorities and Europol should thus only request a comparison with 
Eurodac when they have reasonable grounds to believe that such a comparison will 
provide information that will substantially assist them in preventing, detecting or 
investigating a terrorist offence or other serious criminal offence. 


* 603/2013 recital 32 


(42) In addition, access should be allowed only on condition that comparisons with the 
national fingerprint databases of the Member State and with the automated 
fingerprinting identification Systems of all other Member States under Council 
Decision 2008/615/JHA of 23 June 2008 on the stepping un of cross - bord er 

to the establishment of the identity of the data subject. That condition requires the 
requesting Member State to conduct comparisons with the automated fingerprinting 
identification Systems of all other Member States under Decision 2008/615/JHA which 
are technically available, unless that Member State can justify that there are reasonable 
grounds to believe that it would not lead to the establishment of the identity of the data 
subject. Such reasonable grounds exist in particular where the specific case does not 
present any operational or investigative link to a given Member State. That condition 
requires prior legal and technical implementation of Decision 2008/615/JHA by the 
requesting Member State in the area of fingerprint data, as it should not be pennitted 
to conduct a Eurodac check for law enforcement purposes where those above steps 
have not been first taken. 


Council Decision 2008/615/JHA of 23 June 2008 on the stepping up of cross-border cooperation. 
narticularlv in combating terrorism and cross-border crime 1 0J L 210, 6.8.2008, p. 1). 
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* 603/2013 recital 33 


(43) 


Prior to searching Eurodac, designated authorities should also, provided that the 
conditions for a comparison are met, consult the Visa Information System under 
Council Decision 2008/633/JHA of 23 June 2008 concerning access for consultation 
of the Visa Information System ( VIS) bv designated authoritics of Momber States and 


offences and of other serious criminal offenco s 


41 


* 603/2013 recital 34 _ 

(44) For the purpose of efficiënt comparison and exchange of personal data, Member States 
should fully implement and make use of the existing international agreements as well 
as of Union law concerning the exchange of personal data already in force, in 
particular of Decision 2008/615/JHA. 


* 603/2013 recital 35 _ 

The beot intereoto of the child ohould be a primary conoideration for Member Stateo when 
applying this Regulation. Where the requesting Member State establishes that Eurodac data 
portain to a minor, these data may only bo usod for law onforcomont purposos by the 
requeoting Member State in accordance with that State'o lawo applicable to minoro and 4# 
accordance with the obligation to give primary conoideration to the beot intereoto of the child. 


* 603/2013 recital 36 _ 

(45) While the non-contractual liability of the Union in connection with the operation of 
the Eurodac System will be governed by the relevant provisions of the Treaty on the 
Functioning of the European Union (TFEU), it is necessary to lay down specific rules 
for the non-contractual liability of the Member States in connection with the operation 
of the system. 


i 603/2013 recital 37 (adapted) 

O new 

(46) Since the objective of this Regulation, name ly the creation of a system for the 
comparison of fingerprint O and facial image O data to assist the implementation of 
Union asylum E> and migration <3 policy, cannot, by its very nature, be sufficiently 
achieved by the Member States and can therefore be better achieved at Union level, 
the Union may adopt measures in accordance with the principle of subsidiarity as set 
out in Article 5 of the Treaty on European Union (TEU). In accordance with the 


Council Decision 2008/633/JHA of 23 June 2008 concemine access for consultation of the Visa 
Information System tVISt bv designated authorities of Member States and bv Europol for the mirooses 
of the orevention. detection and investigation of terrorist offences and of other serious criminal offences 
(OJ L 218, 13.8.2008, p. 129). 
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principle of proportionality, as set out in that Article, this Regulation does not go 
beyond what is necessary in order to achieve that objective. 


4^ 603/2013 recital 38 (adapted) 
■=!> new 


(47) [Directive [2016/.../...] of the European Parliament and of the Council of 2 4 Octobcr 

-of-eersonal d ata 


and on the free movement of such da ta 42 ] applies to the processing of personal data by 
the Member States carried out in application of this Regulation unless such processing 
is carried out by the designated or verifying [S> competent <3 authorities of the 
Member States for the purposes of the prevention, E> investigation, <3 detection or 
investigation O prosecution O of terrorist offences or of other serious criminal 
offences O including the safeguarding against and the prevention of threats to public 
security <=■ . 


4^ 603/2013 recital 39 (adapted) 

■=> new 

(48) E> The national provisions adopted pursuant to Directive [2016/... /EU] of the 
European Parliament and of the Council [of ... 2016] on the protection of individuals 
with regard to the processing of personal data by competent authorities for the 
purposes of prevention, investigation, detection or prosecution of criminal offences or 
the execution of criminal penalties, and the free movement of such data apply to <3 
44he processing of personal data by the E> competent <3 authorities of the Member 
States for the purposes of the prevention, IS> investigation, <3 detection or 
investigation O prosecution O of terrorist offences or of other serious criminal 
offences pursuant to this Regulation should bc subject to a Standard of protection of 
p ersonal data undcr their national law which complics with Council Framcwo #h 

Dccision 2008/977/JE1A of 27 November 2008 on the protection of personal data 

proccsscd in the framowork of policc and judicial co opcration in criminal mattors 4 ^. 


(49) 


4» 603/2013 recital 40 (adapted) 
■=> new 


The principlcs ■=> mies <=> set out in Regulation Directive [2016/.../..] 95/46/EC 


regarding the protection of the rights and freedoms of individuals, notably their right 
to E> the protection of personal data concerning them <3 privacy , with regard to the 
processing of personal data should be O specified in respect of the responsibility for 
the processing of the data, of safeguarding the rights of data subjects and of the 
supervision of data protection <=> oupplcmented or clarified , in particular as far as 
certain sectors are concemed. 


Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the 

protection of individuals with regard to the processing of personal data and on the free movement of 

such data t OJL 281. 23.11.1995. p. 311. 

OJ L 350. 30.12.2008. p. 60. 
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* 603/2013 recital 41 
■=> new 


(50) Transfers of personal data obtained by a Member State or Europol pursuant to this 
Regulation from the Central System to any third country or international organisation 
or private entity established in or outside the Union should be prohibited, in order to 
ensure the right to asylum and to safeguard applicants for international protection from 
having their data disclosed to a third country. This implies that Member States should 
not transfer information obtained from the Central System concerning: O the name(s); 
date of birth; nationality; O the Member State(s) of origin O or Member State of 
allocation; the details of the identity or travel document; O ; the place and date of 
application for international protection; the reference number used by the Member 
State of origin; the date on which the fingerprints were taken as well as the date on 
which the Member State(s) transmitted the data to Eurodac; the operator user ID; and 
any information relating to any transfer of the data subject under [Regulation (EU) No 
604/2013]. That prohibition should be without prejudice to the right of Member States 
to transfer such data to third countries to which [Regulation (EU) No 604/2013] 
applies [O in accordance with Regulation (EU) No [.../2016]respectively with the 
national rules adopted pursuant to Directive [2016/.../EU] <=■], in order to ensure that 
Member States have the possibility of cooperating with such third countries for the 
purposes of this Regulation. 


'O new 

(51) In individual cases, information obtained from the Central System may be shared with 
a third-country in order to assist with the identification of a third-country national in 
relation to his/her return. Sharing of any personal data must be subject to strict 
conditions. Where such information is shared, no information shall be disclosed to a 
third-country relating to the fact that an application for international protection has 
been made by a third-country national where the country the individual is being 
readmitted to, is also the individual’s country of origin or another third-country where 
they will be readmitted. Any transfer of data to a third-country for the identification of 
a third-country national must be in accordance with the provisions of Chapter V of 
Regulation (EU) No. [...2016]. 


* 603/2013 recital 42 _ 

(52) National supervisory authorities should monitor the lawfulness of the processing of 
personal data by the Member States, and the supervisory authority set up by Decision 
2009/371/JHA should monitor the lawfulness of data processing activities performed 
by Europol. 


* 603/2013 recital 43 _ 

(53) Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 
Beccmber 2000 on the protection of individuals with rcgard to the processing =of 
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personal data bv the Communitv institutions and bodies and on the free movement of 
such data 44 , and in particular Articles 21 and 22 thereof concerning confidentiality and 
security of processing, applies to the processing of personal data by Union institutions, 
bodies, offices and agencies carried out in application of this Regulation. However, 
certain points should be clarified in respect of the responsibility for the processing of 
data and of the supervision of data protection, hearing in mind that data protection is a 
key factor in the successful operation of Eurodac and that data security, high technical 
quality and lawfulness of consultations are essential to ensure the smooth and proper 
functioning of Eurodac as well as to facilitate the application of [Regulation (EU) No 
604/2013], 


^ 603/2013 recital 44 (adapted) 

O new 

(54) The data subject should be informed O in particular O of the purpose for which his or 
her data will be processed within Eurodac, including a description of the aims of 
Regulation (EU) [.../...] No 601/2013 , and of the use to which law enforcement 
authorities may put his or her data. 


^ 603/2013 recital 45 

(55) It is appropriate that national supervisory authorities monitor the lawfulness of the 
processing of personal data by the Member States, whilst the European Data 
Protection Supervisor, as referred to in Regulation (EC) No 45/2001, should monitor 
the activities of the Union institutions, bodies, offices and agencies in relation to the 
processing of personal data carried out in application of this Regulation. 


ff new 

(56) The European Data Protection Supervisor was consulted in accordance with Article 28(2) 
of Regulation (EC) No 45/2001 and delivered an opinion on [...] 


* 603/2013 recital 46 _ 

(57) Member States, the European Parliament, the Council and the Commission should 
ensure that the national and European supervisory authorities are able to supervise the 
use of and access to Eurodac data adequately. 


^ 603/2013 recital 47 (adapted) 

(58) It is appropriate to monitor and evaluate the perfonnance of Eurodac at regular 
intervals, including in terms of whether law enforcement access has led to indirect 


Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on 
the protection of individuals with regard to the processing of personal data bv the Communitv 
institutions and bodies and on the free movement of such data t OJ L 8, 12.1.2001, p. 1). 
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discrimination against applicants for international protection, as raised in the 
Commission's evaluation of the compliance of this Regulation with the Charter of 
Fundamental Rights of the European Union ('the Charter'). The Age ney E> eu- 
LISA <3 should submit an annual report on the activities of the Central System to the 
European Parliament and to the Council. 


* 603/2013 recital 48 
O new 

(59) Member States should provide for a system of effective, proportionate and dissuasive 
penalties to sanction the ■=> unlawful <=■ processing of data entered in the Central 
System contrary to the purpose of Eurodac. 


* 603/2013 recital 49 _ 

(60) It is necessary that Member States be informed of the status of particular asylum 
procedures, with a view to facilitating the adequate application of Regulation (EU) No 
604/2013. 


^ 603/2013 recital 50 

(61) This Regulation respects the fundamental rights and observes the principles recognised 
in particular by the Charter. In particular, this Regulation seeks to ensure full respect 
for the protection of personal data and for the right to seek international protection, 
and to promote the application of Articles 8 and 18 of the Charter. This Regulation 
should therefore be applied accordingly. 


* 603/2013 recital 51 _ 

(62) In accordance with Articles 1 and 2 of Protocol No 22 on the position of Denmark, 
annexed to the TEU and to the TFEU, Denmark is not taking part in the adoption of 
this Regulation and is not bound by it or subject to its application. 


^ 603/2013 recital 52 (adapted) 

In accordance with Articlo 3 of Protocol No 21 on the position of the United Kingdom and 
Ircland in respect of the Arca of Frccdom, Sccurity and Justicc, annexed to the TEU and =t# 
the TFEU, the United Kingdom has notifiod its wish to tako part in the adoption and 
application of this Regulati es? 


^ 603/2013 recital 53 (adapted) 

In accordance with Articlo 1 and 2 of Protocol No 21 on the position of the United Kingdom 
and Ircland in respect of the Arca of Frccdom, Sccurity and Justicc. annexed to the TEU a nd 
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to the TFEU, and without prcjudicc to Artiele 4 of that Protocol, Ircland is not taking part 4n 
the adoption of this Rogulation and is not bound by it or subject to its application. 


-0- new 

(63) [In accordance with Artiele 3 of Protocol No 21 on the position of the United 
Kingdom and Ireland in respect of the area of freedom, security and justice, annexed 
to the Treaty on European Union and to the Treaty on the Functioning of the European 
Union, those Member States have notified their wish to take part in the adoption and 
application of this Regulation] OR 

(64) [In accordance with Articles 1 and 2 of Protocol No 21 on the position of the United 
Kingdom and Ireland in respect of the area of freedom, security and justice, annexed 
to the Treaty on European Union and to the Treaty on the Functioning of the European 
Union, and without prejudice to Artiele 4 of that Protocol, those Member States are 
not taking part in the adoption of this Regulation and are not bound by it or subject to 
its application.] OR 

(65) [In accordance with Articles 1 and 2 of Protocol No 21 on the position of the United 
Kingdom and Ireland in respect of the area of freedom, security and justice, annexed 
to the Treaty on European Union and to the Treaty on the Functioning of the European 
Union, and without prejudice to Artiele 4 of that Protocol, the United Kingdom is not 
taking part in the adoption of this Regulation and is not bound by it or subject to its 
application. 

(66) In accordance with Artiele 3 of Protocol No 21 on the position of the United Kingdom 
and Ireland in respect of the area of freedom, security and justice, annexed to the 
Treaty on European Union and to the Treaty on the Functioning of the European 
Union, Ireland has notified (, by letter of...,) its wish to take part in the adoption and 
application of this Regulation.] OR 

(67) [In accordance with Artiele 3 of Protocol No 21 on the position of the United 
Kingdom and Ireland in respect of the area of freedom, security and justice, annexed 
to the Treaty on European Union and to the Treaty on the Functioning of the European 
Union, the United Kingdom has notified (, by letter of ...,) its wish to take part in the 
adoption and application of this Regulation. 

(68) In accordance with Articles 1 and 2 of Protocol No 21 on the position of the United 
Kingdom and Ireland in respect of the area of freedom, security and justice, annexed 
to the Treaty on European Union and to the Treaty on the Functioning of the European 
Union, and without prejudice to Artiele 4 of that Protocol, Ireland is not taking part in 
the adoption of this Regulation and is not bound by it or subject to its application.] 


^ 603/2013 recital 54 (adapted) 


(69) It is appropriate to restrict the territorial scope of this Regulation so as to align it on 
the territorial scope of Regulation (EU) No [.../...] 
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* 603/2013 (adapted) 

HAVE ADOPTED THIS REGULATION: 

CHAPTERI 

GENERAL PROVISIONS 


Article 1 

Purpose of "Eurodac" 

1. A system known as "Eurodac" is hereby established, the purpose of which shall be to; 

(a) assist in detennining which Member State is to be responsible pursuant to Regulation 
(EU) No 601/2013 for examining an application for international protection 

lodged in a Member State by a third-country national or a stateless person, and 
otherwise to facilitate the application of Regulation (EU) No 601/2013 under 

the conditions set out in this Regulation?; 


-0- new 

(b) assist with the control of illegal immigration to and secondary movements within the 
Union and with the identification of illegally staying third-country nationals for 
detennining the appropriate measures to be taken by Member States, including 
removal and repatriation of persons residing without authorisation. 


* 603/2013 (adapted) 

■=> new 

i (g) This Rugulation also lays down the conditions under which Member States’ 
designated authorities and the European Police Office (Europol) may request the 
comparison of fingerprint O and facial image O data with those stored in the Central 
System for law enforcement purposes ■=> for the prevention, detection or 
investigation of terrorist offences or of other serious criminal offences <=■ . 

3/2 . Without prejudice to the processing of data intended for Eurodac by the Member State of 
origin in databases set up under the latter's national law, fingerprint data and other personal 
data may be processed in Eurodac only for the purposes set out in this Regulation and [Article 
34(1) of Regulation (EU) No 604/2013]. 


Article 2 

Obligation to take fingerprints and a facial image 

1. Member States are obliged to take the fingerprints and facial image of persons referred 
to in Article 10(1), 13(1) and 14(1) for the purposes of Article l(l)(a) and (b) of this 
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Regulation and shall impose on the data-subject the requirement to provide his or her 
fingerprints and a facial image and inform them as such in accordance with Article 30 of this 
Regulation. 

2. Taking fingerprints and facial images of minors from the age of six shall be carried 
out in a child-friendly and child-sensitive marnier by officials trained specifically to enrol 
minor's fingerprints and facial images. The minor shall be informed in an age-appropriate 
marnier using leaflets and/or infographics and/or demonstrations specifically designed to 
explain the fingerprinting and facial image procedure to minors and they shall be 
accompanied by a responsible adult, guardian or representative at the time their fingerprints 
and facial image are taken. At all times Member States must respect the dignity and physical 
integrity of the minor during the fingerprinting procedure and when capturing a facial image. 

3. Member States may introducé administrative sanctions, in accordance with their 
national law, for non-compliance with the fingerprinting process and capturing a facial image 
in accordance with paragraph 1 of this Article. These sanctions shall be effective, 
proportionate and dissuasive. In this context, detention should only be used as a means of last 
resort in order to detennine or verify a third-country national's identity. 

4. Without prejudice to paragraph 3 of this Article, where enrolment of the fingerprints 
or facial image is not possible from third-country nationals who are deemed to be vulnerable 
persons and from a minor due to the conditions of the fingertips or face, the authorities of that 
Member State shall not use sanctions to coerce the taking of fingerprints or a facial image. A 
Member State may attempt to re-take the fingerprints or facial image of a minor or vulnerable 
person who refuses to comply, where the reason for non-compliance is not related to the 
conditions of the fingertips or facial image or the health of the individual and where it is duly 
justified to do so. Where a minor, in particular an unaccompanied or separated minor refuses 
to give their fingerprints or a facial image and there are reasonable grounds to suspect that 
there are child safeguarding or protection risks, the minor shall be referred to the national 
child protection authorities and /or national referral mechanisms. 


* 603/2013 
O new 

5. The procedure for taking fingerprints O and a facial image <p shall be detennined and 
applied in accordance with the national practice of the Member State concerned and in 
accordance with the safeguards laid down in the Charter of Fundamental Rights of the 
European Union, in the Convention for the Protection of Human Rights and Fundamental 
Freedoms and in the United Nations Convention on the Rights of the Child. 

Article £ 3 

Definitions 

1. For the purposes of this Regulation: 

(a) 'applicant for international protection’ means a third-country national or a stateless 
person who has made an application for international protection as defined in Article 
2(h) of Directive 2011/95/EU in respect of which a final decision has not yet been 
taken; 

(b) ’Member State of origin’ means: 
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(i) in relation to a person covered by Article 9 JJ)(1), the Member State which 
transmits the personal data to the Central System and receives the results of the 
comparison; 

(ii) in relation to a person covered by Article M 11(1), the Member State which 
transmits the personal data to the Central System O and receives the results of 
the comparison <=> ; 

(iii) in relation to a person covered by Article ö 14(1), the Member State 
which transmits the personal data to the Central System and receives the results 
of the comparison; 


1 new 

(c) ‘third-country national’ means any person who is not a Citizen of the Union 
within the meaning of Article 20(1) of the Treaty and who is not a national of a State 
which participates in this Regulation by virtue of an agreement with the European 
Union; 


1 new 

(d) ’illegal stay' means the presence on the territory of a Member State, of a third- 
country national who does not fulfïll, or no longer fulfils the conditions of entry as set 
out in Article 5 of the Schengen Borders Code or other conditions for entry, stay or 
residence in that Member State; 


* 603/2013 (adapted) 

■=> new 

(eefbeneficiary of international protection’ means a third-country national or a 
stateless person who has been granted international protection as delined in Article 
2(a) of Directive 2011/95/EU; 

(ëfl’hif means the existence of a match or matches established by the Central System 
by comparison between fingerprint data recorded in the computerised central 
database and those transmitted by a Member State with regard to a person, without 
prejudice to the requirement that Member States shall immediately check the results 
of the comparison pursuant to Article M 26(4); 

(#g)'Naüonal Access Poinf means the designated national system which 
communicates with the Central System; 

(Ih) 'Agoncy' IS> ’eu-LISA’ <3 means the E> European <3 Agency E> for the 
operational management of large-scale infonnation Systems in the area of freedom, 
security and justice <3 established by Regulation (EU) No 1077/2011; 

(gO'Europof means the European Police Office established by Decision 
2009/371/JHA; 
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(bj ['Eurodac data' means all data stored in the Central System in accordance with 
Article M12* Article M 12(2) ■=> and Article 14(2) <p ; 

(jk) 'law enforcement’ means the prevention, detection or investigation of terrorist 
offences or of other serious criminal offences; 

(jl) 'terrorist offences' means the offences under national law which correspond or are 
equivalent to those referred to in Articles 1 to 4 of Framework Decision 
2002/475/JHA; 

(km)'serious criminal offences' means the forms of crime which correspond or are 
equivalent to those referred to in Article 2(2) of Framework Decision 2002/5 84/JFIA, 
if they are punishable under national law by a custodial sentence or a detention order 
for a maximum period of at least three years; 

(In)'fingerprint data' means the data relating to O plain and rolled impressions of 
the <=■ fingerprints of all O ten fingers, where present O or at least the index fingers f 
and if thooc are missing, the prints of all other fingero of a peroon , or a latent 
fingcrprint?; 


2 new 

(o) facial image means digital images of the face with sufficiënt image resolution and quality 
to be used in automatic biometric matching. 


* 603/2013 (adapted) 

■=> new 

2. The terms defined in Article [,.]3 of Directive [2016/.../EU[ 95M6/EC shall have the same 
meaning in this Regulation in so far as personal data are processed by the authorities of the 
Member States for the purposes laid down in Article I (1 )(a) of this Regulation. 

3. Unless stated otherwise, the terms defined in Article [,.]2 of Regulation (EU) No [.../...] 
601/2013 shall have the same meaning in this Regulation. 

4. The terms defined in Article [...] 3 of Directive [2016/.../EU] Framework Decision 
2008/977/JHA shall have the same meaning in this Regulation in so far as personal data are 
processed by the IE> competent <3 authorities of the Member States for the purposes laid 
down in Article l £3¥D(c) of this Regulation. 

Article S £ 

System architecture and basic principles 

1. Eurodac shall consist of: 

(a) a computerised central fmgerprint database ("Central System") composed of: 

(i) a Central Unit, 

(ii) a Business Continuity Plan and System; 

(b) a communication infrastructure between the Central System and Member States 
that provides an encryptcd Virtual notwork dcdicatcd to ■=> a secure and encrypted 
communication channel for <=> Eurodac data ("Communication Infrastructure"). 
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-O- new 

2. The EURODAC Communication Infrastructure will be using the existing 'Secure Trans 
European Services for Telematics between Administrations' (TESTA) network. A separate 
Virtual private network dedicated to the EURODAC shall be established on the existing 
TESTA private virtual network to ensure the logical separation of EURODAC data from 
other data. 


* 603/2013 _ 

23 . Each Member State shall have a single National Access Point. 

M- Data on persons covered by Articles 4 10(1), M 11(1) and ö M(l) which are processed 
in the Central System shall be processed on behalf of the Member State of origin under the 
conditions set out in this Regulation and separated by appropriate technical means. 

45 . The rules goveming Eurodac shall also apply to operations carried out by the Member 
States as from the transmission of data to the Central System until use is made of the results 
of the comparison. 


* 603/2013 (adapted) 


Article 4 5 

Operational management 

1. The Agoncy IE> eu-LISA <3 shall be responsible for the operational management of 
Eurodac. 

The operational management of Eurodac shall consist of all the tasks necessary to keep 
Eurodac functioning 24 hours a day, 7 days a week in accordance with this Regulation, in 
particular the maintenance work and technical developments necessary to ensure that the 
System functions at a satisfactory level of operational quality, in particular as regards the time 
required for interrogation of the Central System. A Business Continuity Plan and System shall 
be developed taking into account maintenance needs and unforeseen downtime of the System, 
including the impact of business continuity measures on data protection and security. 

The Agoncy E> 2. eu-LISA <3 shall ensure, in cooperation with the Member States, that at 
all times the best available and most secure technology and techniques, subject to a cost- 
benefit analysis, are used for the Central System. 



■0- new 


2. Eu-LISA shall be permitted to use real personal data ol 

f the Eurodac production system for 


testing purposes in the following circumstances: 

(a) for diagnostics and repair when faults are discovered with the Central System; and 
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(b) for testing new technologies and techniques relevant to enhance the performance of the 
Central System or transmission of data to it. 

In such cases, the security measures, access control and logging activities at the testing 
environment shall be equal to the ones for the Eurodac production system. Real personal data 
adopted for testing shall be rendered anonymous in such a way that the data-subject is no 
longer identifiable. 


* 603/2013 (adapted) _ 

23 . The Agcn ey [B> eu-LISA <3 shall be responsible for the following tasks relating to the 
Communication Infrastructure: 

(a) supervision; 

(b) security; 

(c) the coordination of relations between the Member States and the provider. 

34 . The Commission shall be responsible for all tasks relating to the Communication 
Infrastructure other than those referred to in paragraph 3 3, in particular: 

(a) the implementation of the budget; 

(b) acquisition and renewal; 

(c) contractual matters. 


-0- new 

5. A separate secure electronic transmission channel between the authorities of Member 
States known as the ‘DubliNet’ communication network set-up under [Article 18 of 
Regulation (EC) No. 1560/2003] for the purposes set out in Articles 32, 33 and 46 of 
Regulation (EU) No. shall also be operated and managed by eu-LISA. 


* 603/2013 (adapted) 

■=> new 

46 . Without prejudice to Article 17 of the Staff Regulations, the Agcn ey E> eu-LISA <3 
shall apply appropriate rules of professional secrecy or other equivalent duties of 
confidentiality to all its staff required to work with Eurodac data. This obligation shall also 
apply after such staff leave office or employment or after the tennination of their duties. 

Article S 6 

Member States' designated authorities for law enforcement purposes 

1. For the purposes laid down in Article l (3¥l)(c). Member States shall designate the 
authorities that are authorised to request comparisons with Eurodac data pursuant to this 
Regulation. Designated authorities shall be authorities of the Member States which are 
responsible for the prevention, detection or investigation of terrorist offences or of other 
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serious criminal offences. Designated authorities shall not include agencies or units 
exclusively responsible for intelligence relating to national security. 

2. Each Member State shall keep a list of the designated authorities. 

3. Each Member State shall keep a list of the operating units within the designated authorities 
that are authorised to request comparisons with Eurodac data through the National Access 
Point. 


Article 4 7 

Member States' verifying authorities for law enforcement purposes 

1. For the purposes laid down in Article l t^tlkck each Member State shall designate a 
single national authority or a unit of such an authority to act as its verifying authority. The 
verifying authority shall be an authority of the Member State which is responsible for the 
prevention, detection or investigation of terrorist offences or of other serious criminal 
offences. 

The designated authority and the verifying authority may be part of the same organisation, if 
permitted under national law, but the verifying authority shall act independently when 
perfonning its tasks under this Regulation. The verifying authority shall be separate from the 
operating units referred to in Article i 6(3) and shall not receive instructions from them as 
regards the outcome of the verification. 

Member States may designate more than one verifying authority to reflect their organisational 
and administrative structures, in accordance with their constitutional or legal requirements. 

2. The verifying authority shall ensure that the conditions for requesting comparisons of 
fingerprints with Eurodac data are fulfïlled. 

Only duly empowered staff of the verifying authority shall be authorised to receive and 
transmit a request for access to Eurodac in accordance with Article W 20. 

Only the verifying authority shall be authorised to forward requests for comparison of 
fingerprints O and facial images <=■ to the National Access Point. 

Article 2 8 

Europol 

1. For the purposes laid down in Article l Q¥l¥ch Europol shall designate a specialised unit 
with duly empowered Europol officials to act as its verifying authority, which shall act 
independently of the designated authority referred to in paragraph 2 of this Article when 
perfonning its tasks under this Regulation and shall not receive instructions from the 
designated authority as regards the outcome of the verification. The unit shall ensure that the 
conditions for requesting comparisons of fingerprints O and facial images O with Eurodac 
data are fulfïlled. Europol shall designate in agreement with any Member State the National 
Access Point of that Member State which shall communicate its requests for comparison of 
fingerprint O and facial image O data to the Central System. 

2. For the purposes laid down in Article I ft) (1 )fc) . Europol shall designate an operating unit 
that is authorised to request comparisons with Eurodac data through its designated National 
Access Point. The designated authority shall be an operating unit of Europol which is 
competent to collect, store, process, analyse and exchange information to support and 
strengthen action by Member States in preventing, detecting or investigating terrorist offences 
or other serious criminal offences falling within Europol’s mandate. 
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Article S £ 

Statistics 

1. The Agcn ey E> eu-LISA <3 shall draw up statistics on the work of the Central System 
every O month O quarter , indicating in particular: 

(a) the number of data sets transmitted on persons referred to in Articles g K)( 1), M 
11(1) and |M(1); 

(b) the number of hits for applicants for international p rot eet io n E> persons referred 
to in Article 10(1) <KI who have IE> subsequently <E1 lodged an application for 
international protection in another Member State O , who were apprehended in 
connection with the irregular Crossing of an external border and who were found 
illegally staying in a Member State <=■ ; 

(c) the number of hits for persons referred to in Article 44 11(1) who have 
subsequently lodged an application for international protection O who were 
apprehended in connection with the irregular Crossing of an external border and who 
were found illegally staying in a Member State <=■ ; 

(d) the number of hits for persons referred to in Article W 14(1) who had previously 
lodged an application for international protection in another Member State O , who 
were apprehended in connection with the irregular Crossing of an external border and 
who were found illegally staying in a Member State <=■ ; 

(e) the number of fingerprint data which the Central System had to request more than 
once from the Member States of origin because the fingerprint data originally 
transmitted did not lend themselves to comparison using the computerised fingerprint 
recognition system; 

(f) the number of data sets marked, unmarked, blocked and unblocked in accordance 
with Article Ö 1£(1) and (3} O 17(2), (3) and (4) <=■ ; 

(g) the number of hits for persons referred to in Article 44 19(1) O and (4) O for 
whom hits have been recorded under points (b) ■=> , (c) <=■ and (d) of this Article; 

(h) the number of requests and hits referred to in Article 21111; 

(i) the number of requests and hits referred to in Article W 22(14: 


-0- new 

(j) the number of requests made for persons referred to in Article 31; 

(h) the number of hits received from the Central System as referred to in Article 26(6). 


* 603/2013 (adapted) 

■=> new 

2. O The monthly statistical data for persons referred to in paragraphl(a) to (h) shall be 
published and made public by each month. <p At the end of each year, \E> the yearly <3 
statistical data O for persons referred to in paragraph l(a) to (h) O shall be O published and 
made public by eu-LISA <=■ ee4# klishod in the fbrm of a u -w mpilation of the qi ;-- : rlerly statistics 
for that year, including an indication of the number of peroono for whom hito have been 
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recorded under paragraph l(b), (c) and (d) . The statistics shall contain a breakdown of data for 
each Member State. The rosults shall bo made public. 


-0- new 

3. At the request of the Commission, eu-LISA shall pro vide it with statistics on specific 
aspects for research and analysis purposes without allowing for individual identification as 
well as the possibility to produce regular statistics pursuant to paragraph 1. These statistics 
shall be shared with other Justice and Home Affairs Agencies if they are relevant for the 
implementation of their tasks. 


* 603/2013 (adapted) 
O new 


CHAPTERII 

APPLICANTS FOR INTERNA TIONAL PROTECTION 


Article g 10 

Collectioni \E> and <E1 transmission and eomparison of fingerprints IE> and facial image 

data <3 

1. Each Member State shall promptly take the fingerprints of all fingers ■=> and capture a 
facial image <=■ of every applicant for international protection of at least 44 4> six <=> years of 
age and shall, as soon as possible and no later than 72 hours after the lodging of his or her 
application for international protection, as defined by Article [21(2)]of Regulation (EU) No 
601/2013 , transmit them together with the data referred to in Article 4+ 12 (b) to (g) O (c) to 
(n) O of this Regulation to the Central System. 

Non-compliance with the 72-hour time-limit shall not relieve Member States of the obligation 
to take and transmit the fingerprints to the Central System. Where the condition of the 
fingertips does not allow the taking of the fingerprints of a quality ensuring appropriate 
eomparison under Article M 26, the Member State of origin shall retake the fingerprints of 
the applicant and resend them as soon as possible and no later than 48 hours after they have 
been successfully retaken. 

2. By way of derogation from paragraph 1, where it is not possible to take the fingerprints 
O and facial image O of an applicant for international protection on account of measures 
taken to ensure his or her health or the protection of public health, Member States shall take 
and send such fingerprints O and facial image O as soon as possible and no later than 48 
hours after those health grounds no longer prevail. 

In the event of serious technical problems, Member States may extend the 72-hour time-limit 
in paragraph 1 by a maximum of a further 48 hours in order to carry out their national 
continuity plans. 

3. Fingerprint data within the meaning of Article 11 (a) tranomitted by any Member State, with 
the exception of those transmitted in accordance with Article 10(b), shall be compar eë 
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automatically with the fingerprint data transmittcd by othcr Mcmbcr States and alrcady stor eé 
in the Central System. 

4. The Central System shall ensure, at the request of a Mcmbcr State that the comparis on 
referred to in pia ^ graph 3 covers the fingerprint data provmusly transmittcd by that Memb 
State, in addition to the data from othcr Mcmbcr Statesv 

5. The Central System shall automatically transmit the hit or the negative result of the 
comparison to the Mcmbcr State of origin. Where there is a hit, it shall transmit for all da ta 
sets corresponding to the hit the da t a referred to ia =A #ticlo 11 (a) to (k) along with, 
appropriatc, the mark referred to in Artiele 18 ft=F 


-0- new 

3. Fingerprint data may also be taken and transmitted by members of the European Border 
[and Coast] Guard Teams or by Member State asylum experts when performing tasks and 
exercising powers in accordance with [Regulation on the European Border [and Coast] Guard 
and repealing Regulation (EC) No 2007/2004, Regulation (EC) No 863/2007 and Council 
Decision 2005/267/EC] and [Regulation (EU) No. 439/2010], 


* 603/2013 (adapted) 
■=> new 


Artiele M 11 

Information on the status of the data subject 

The following infonnation shall be sent to the Central System in order to be stored in 
accordance with Artiele ö 17 (T) for the purpose of transmission under Articles 9^ O 15 
and 16 O : 

(a) when an applicant for international protection or another person as referred to in 
■=> Artiele 21(1) <p ■=> (b), (c), <=> (d) ■=> or (e) <=> of Regulation (EU) No [.../...] 
601/2013 arrivés in the Member State responsible following a transfer pursuant to s 
decision a # coding to a take back request O notification <=> as referred to in Artiele 
O 26 O thereof, the Member State responsible shall update its data set recorded in 
conformity with Artiele 4=1= 12 o 1' this Regulation relating to the person concerned by 
adding his or her date of arrival; 

(b) when an applicant for international protection arrivés in the Member State 
responsible following a transfer pursuant to a decision acceding to a take charge 
request according to Artiele O 24 O of Regulation (EU) No [.../...] 601/2013 , the 
Member State responsible shall send a data set recorded in conformity with Artiele 

12 of this Regulation relating to the person concerned and shall include his or her 
date of arrival; 
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-O- new (adapted) 

(c) when an applicant for international protection arrivés in the Member State of 
allocation pursuant to Article 34 of Regulation (EU) No. 601/2013 , that 

Member State shall send a data set recorded in confonnity with Article 12 of this 
Regulation relating to the person concerned and shall include his or her date of 
arrival and record that it is the Member State of allocation. 


* 603/2013 (adapted) 

O new 

(c) as soon as the Momber State of origin ostablishos that the person concerned 
whosc data was recorded in Eurodac in accordancc with Article 11 of this Regula tion 
has loft the torritory of the Momber Statos, it shall update its data set recorded in 
conformity with Article 11 of this Regulation relating to the person concerned-by 
adding the date when that person left the territory, in order to facilitatc the 
application of Articles 19(2) and 20(5) of Regulation (EU) No 604/2013 = 

(d) as soon as the Member State of origin ensures that the person concerned whose 
data was recorded in Eurodac in accordance with Article M12 of this Regulation has 
left the territory of the Member States in compliance with a return decision or 
removal order issued following the withdrawal or rejection of the application for 
international protection as providod for in Article 19(3) of Regulation (EU) No 
604/2013 , it shall update its data set recorded in conformity with Article ö 12 of this 
Regulation relating to the person concerned by adding the date of his or her removal 
or when he or she left the territory; 

(e) the Member State which becomes responsible in accordance with O Article 
19(1) O of Regulation (EU) No [.../...] 601/2013 shall update its data set recorded 
in confonnity with Article ^ 12 of this Regulation relating to the applicant for 
international protection by adding the date when the decision to examine the 
application was taken. 


Article ö 22 

Recording of data 

Only the following data shall be recorded in the Central System: 
(a) fmgerprint data; 



aliases, which may be entered separately; 

(d) nationality(ies); 

(e) place and date of birth; 
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(M) Member State of origin, place and date of the application for international 
protection; in the cases referred to in Article W 1 l(b), the date of application shall be 
the one entered by the Member State who transferred the applicant; 

(tg) sex; 



(j) unique application number of the application for international protection pursuant 


to Article 22(2) of Regulation (EU) No. [.../...] 601/2013 ; 

(k) the Member State of allocation in accordance with Article 1 l(c); 


* 603/2013 (adapted) 

■=> new 

(#1) date on which the lingerprints O and/or facial image <=" were taken; 

( fm) date on which the data were transmitted to the Central System; 

(en ) operator user ID; 

(fao ) where applicable in accordance with Article =W JJJa) or (b) , the date of the 
arrival of the person concerned after a successful transfer; 

E> (p) where applicable in accordance with Article 4=0 1 Kb), the date of the arrival 
of the person concerned after a successful transfer; <3 


43 new 

(q) where applicable in accordance with Article 11 (c), the date of the arrival of the 
person concerned after a successful transfer; 
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* 603/2013 (adapted) 

■=> new 

(i) where applicable in accordance with Article 10(c), the date when the peroon 
eoncemed left the territory of the Member States; 

(|r) where applicable in accordance with Article Ml _LL(d), the date when the person 
eoncemed left or was removed from the territory of the Member States; 

(ks) where applicable in accordance with Article Ml il(e), the date when the decision 
to examine the application was taken. 

CHAPTERIII 

THIRD-COUNTR YNA TIONALS OR STA TELESS PERSONS 
APPREHENDED IN CONNECTION WITH THE IRREGULAR CROSSING 

OFANEXTERNAL BORDER 


Article M/ 13 

Collection and transmission of fingerprint data \E> and facial image data <KI 

1. Each Member State shall promptly take the fingerprints of all fingers ■=> and capture a 
facial image <=> of every third-country national or stateless person of at least 44 O six <=> years 
of age who is apprehended by the competent control authorities in connection with the 
irregular Crossing by land, sea or air of the border of that Member State having come from a 
third country and who is not tumed back or who remains physically on the territory of the 
Member States and who is not kept in custody, confinement or detention during the entirety of 
the period between apprehension and removal on the basis of the decision to turn him or her 
back. 

2. The Member State eoncemed shall, as soon as possible and no later than 72 hours after the 
date of apprehension, transmit to the Central System the following data in relation to any 
third-country national or stateless person, as referred to in paragraph 1, who is not tumed 
back: 

(a) fingerprint data; 


(b) a facial image; 
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(c) sumame(s) and forename(s), name(s) at birth and previously used names and 


any aliases, which may be entered separately; 

(d) nationality(ies); 

(e) place and date of birth 


* 603/2013 

( M ) Member State of origin, place and date of the apprehension; 
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(tg) sex; 


-O- new 

(h) type and number of identity or travel document; three letter code of the issuing 
country and validity; 


* 603/2013 
O new 

(|Ü) reference number used by the Member State of origin; 

(gj) date on which the fingerprints O and/or facial image <=■ were taken; 
(fk) date on which the data were transmitted to the Central System; 

(gl) operator user IDg 


-h new 

(m) where applicable in accordance with paragraph 6, the date when the person 
concemed left or was removed from the territory of the Member States. 


* 603/2013 
■=> new 

3. By way of derogation from paragraph 2, the data specified in paragraph 2 relating to 
persons apprehended as described in paragraph 1 who remain physically on the territory of the 
Member States but are kept in custody, confinement or detention upon their apprehension for 
a period exceeding 72 hours shall be transmitted before their release from custody, 
confinement or detention. 

4. Non-compliance with the 72-hour time-limit referred to in paragraph 2 of this Article shall 
not relieve Member States of the obligation to take and transmit the fingerprints to the Central 
System. Where the condition of the fingertips does not allow the taking of fingerprints of a 
quality ensuring appropriate comparison under Article M 26, the Member State of origin shall 
retake the fingerprints of persons apprehended as described in paragraph 1 of this Article, and 
resend them as soon as possible and no later than 48 hours after they have been successfully 
retaken. 

5. By way of derogation from paragraph 1, where it is not possible to take the fingerprints 
O and facial image O of the apprehended person on account of measures taken to ensure his 
or her health or the protection of public health, the Member State concemed shall take and 
send such fingerprints O and facial image <=■ as soon as possible and no later than 48 hours 
after those health grounds no longer prevail. 

In the event of serious technical problems, Member States may extend the 72-hour time-limit 
in paragraph 2 by a maximum of a further 48 hours in order to carry out their national 
continuity plans. 
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6. As soon as the Member State of origin ensures that the person concerned whose data was 
recorded in Eurodac in accordance with paragraph (1) has left the territory of the Member 
States in compliance with a return decision or removal order, it shall update its data set 
recorded in conformity with paragraph (2) relating to the person concerned by adding the date 
of his or her removal or when he or she left the territory. 

7. Fingerprint data may also be taken and transmitted by members of the European Border 
[and Coast] Guard Teams when perfonning tasks and exercising powers in accordance with 
[Regulation on the European Border [and Coast] Guard and repealing Regulation (EC) No 
2007/2004, Regulation (EC) No 863/2007 and Council Decision 2005/267/EC]. 


* 603/2013 (adapted) 


Articlc 15 

Rccording of data 

1. The data rcferrcd to in Articlc 14(2) shall be recorded in the Central System. 

Without prejudice to Article 8, data transmitted to the Central System purouant to Article 
11(2) shall be recorded solely for the purposes of comparison with data on applicants for 
intora ateta aal protoction subscquontly tr & nsmittod to the Cent .4=Sf ,tcm and for the purpooeo 
laid down in Article 1(2). 

The Central System shall not comparo data transmitted to it purouant to Articlc 11(2) with any 
data prcviously recorded in the Central System, or with data subsequently transmitted to t he 
Central System purouant to Article 11(2). 

2. As regards the comparison of data on applicants for international protection subsequen tly 
w& nomittod to the Cent ml Sy s tem ' :lh the data roferred to in pa ra graph 1, the procedur e 
provided for in Article 9(3) and (5) and in Article 25(4) shall apply^ 


Articlc 16 



1. Each oet of data relating to a third - country national or otateleoo peroon ao referred to in 


Article 11(1) ohall be otored in the Central System for 18 montho from the date on which hio 
or her fingerprints woro taken. Upon expiry of that poriod, the Central System shall 
automatically eraoe such data. 

2. The data relating to a third - country' national or otateleoo peroon ao referred to in Article 
1 4 (1) shall be erased from the Central System in accordance with Article 28(3) as soon as t he 
Momber S: te of origin bocomeo av = :re of onc of the folio ng circum -^u xcs beforo the 18 
month period referred to in paragraph 1 of this Article has expireck 

(a) the third - country r^ k*& al or stateloos person h - as been issued with a reoidence 
document; 

(b) the third - country na t ional or owfeleoo per *n=l, s left the territory of the Momber 

* 

k? i m v o • 
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CHAPTERIV 


THIRD-COUNTR YNA TIONALS OR STATELESS PERSONS FOUND 
ILLEGALL YSTA YING IN A MEMBER STA TE 


Article ö IA 

Comparison \E> Collection and transmission <3 of fingerprint \E> and facial image <3 

































































-O- new 

1. Each Member State shall promptly take the fingerprints of all fingers and capture a facial 
image of every third-country national or stateless person of at least six years of age who is 
found illegally staying within its territory. 

2. The Member State concemed shall, as soon as possible and no later than 72-hours 
after the date of apprehension, transmit to the Central System the following data in relation to 
any third-country national or stateless person, as referred to in paragraph 1: 

(a) fmgerprint data; 

(b) a facial image; 

(c) sumame(s) and forename(s), name(s) at birth and previously used names and any 
aliases, which may be entered separately; 

(d) nationality(ies); 

(e) place and date of birth 

(f) Member State of origin, place and date of the apprehension; 

(g) sex; 

(h) type and number of identity or travel document; three letter code of the issuing 
country and validity; 

(i) reference number used by the Member State of origin; 

(j) date on which the fingerprints and/or facial image were taken; 

(k) date on which the data were transmitted to the Central System; 

(l) operator user ID; 

(m) where applicable in accordance with paragraph 6, the date when the person concerned 
left or was removed from the territory of the Member States 


* 603/2013 (adapted) 

O new 

3. The fmgerprint data of a third-country national or a stateless person as referred to in 
paragraph 1 shall be transmitted to the Central System oolely for the purpooe of comparioon 
O and compared <=> with the fmgerprint data of applicants for international protcction 
IE> persons fingerprinted for the purposes of Article ö JJ1(1), M 11(1) and W M(l) <3 
transmitted by other Member States and already recorded in the Central System. 

The fmgerprint data of ouch a third country national or a otateleoo person shall not be recorded 
in the Central System, nor shall they be compared with the data transmitted to the Cent ral 
System pursuant to Article 1 d (2). 


1 new 

4. Non-compliance with the 72-hour time-limit referred to in paragraph 3 of this Article shall 
not relieve Member States of the obligation to take and transmit the fingerprints to the Central 
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System. Where the condition of the fingertips does not allow the taking of fingerprints of a 
quality ensuring appropriate comparison under Article 26, the Member State of origin shall 
retake the fingerprints of persons apprehended as described in paragraph 1 of this Article, and 
resend them as soon as possible and no later than 48 hours after they have been successfully 
retaken. 

5. By way of derogation from paragraph 1, where it is not possible to take the fingerprints 
and facial image of the apprehended person on account of measures taken to ensure his or her 
health or the protection of public health, the Member State concemed shall take and send such 
fingerprints and facial image as soon as possible and no later than 48 hours after those health 
grounds no longer prevail. 

In the event of serious technical problems, Member States may extend the 72-hour time-limit 
in paragraph 2 by a maximum of a further 48 hours in order to carry out their national 
continuity plans. 

6. As soon as the Member State of origin ensures that the person concerned whose data was 
recorded in Eurodac in accordance with Article 13(1) of this Regulation has left the territory 
of the Member States in compliance with a return decision or removal order, it shall update its 
data set recorded in conformity with paragraph 2 of this Article relating to the person 
concemed by adding the date of his or her removal or when he or she left the territory. 


* 603/2013 (adapted) 

■=> new 

4? Onco the rosults of the comparison of fingorprint data havo been transmittod to the Momber 
State of origin, the record of the search shall be kept by the Central System only for the 
purposos of Article 28. Othcr than fbr those purposes, no other record rf4ho scarch may be 
otored either by Member States or by the Central System. 

5. Ao regardo the comparioon of fingerprint data tranomitted under thio Article with the 
fingorprint data of applicants for international protoction transmittod by othor Momber States 
which have alrcady been stored in the Central System, the procedures provided for in Arti de 
9(3) and (5) and in = Articlo 25(1) shall apply. 

CHAPTER V 

\E> PROCEDURE FOR COMPARISON OF DATA FOR APPLICANTS 
FOR INTERNATIONAL PROTECTION AND THIRD-COUNTRY 
NATIONALS APPREHENDED CROSSING THE BORDER 
IRREGULARLY OR ILLEGALLY STAYING IN THE TERRITORY OF 

A MEMBER STATE <3 

Article 15 

[H> Comparison of fingerprint and facial image data <3 

3=1 . Fingerprint O and facial image O data within the moaning of Articlc 11 (a) transmitted by 
any Member State, with the exception of those transmitted in accordance with Article B) 
1 lfb) O and (c) O , shall be compared automatically with the fingerprint data transmitted by 
other Member States and already stored in the Central System E> in accordance with Article 
g lfi(l), ÉÉ 11(1) and ±3 14(1) <3 . 
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42 . The Central System shall ensure, at the request of a Member State, that the comparison 
referred to in paragraph 4 1 E> of this Article <3 covers the fingerprint O and facial image <=■ 
data previously transmitted by that Member State, in addition to the E> fingerprint <3 O and 
facial image <=■ data from other Member States. 

43 . The Central System shall automatically transmit the hit or the negative result of the 
comparison to the Member State of origin O following the procedures set out in Article 
26(4) <=■ . Where there is a hit, it shall transmit for all data sets corresponding to the hit the 
data referred to in Article 1 l(a) to (k) O 12, 13(2) and 14(2) O along with, where appropriate, 
the mark referred to in Article 44 1911 ) O and (4) <4 . 4> Where a negative hit result is 
received, the data referred to in Article 12, 13(2) and 14(2) shall not be transmitted. <=■ 


-0- new 

4. Where evidence of a hit is received by a Member State from Eurodac that can assist 
that Member State to carry out its obligations under Article 1(1 )(a), that evidence shall take 
precedence over any other hit received. 


-0- new 

Article 16 

Comparison of facial image data 

(1) Where the condition of the fingertips does not allow for the taking of fingerprints of 
a quality ensuring appropriate comparison under Article 26 or where a person 
referred to in Article 10(1), 13(1) and 14(1) refuses to comply with the fingerprinting 
process, a Member State may carry out a comparison of facial image data as a last 
resort. 


(2) Facial image data and data relating to the sex of the data-subject may be compared 
automatically with the facial image data and personal data relating to the sex of the 
data-subject transmitted by other Member States and already stored in the Central 
System in accordance with Article 10(1), 13(1) and 14(1) with the exception of those 
transmitted in accordance with Article 11 (b) and (c). 


(3) The Central System shall ensure, at the request of a Member State that the 
comparison referred to in paragraph 1 of this Article covers the facial image data 
previously transmitted by that Member State, in addition to the facial image data 
from other Member States. 


(4) The Central System shall automatically transmit the hit or the negative result of the 
comparison to the Member State of origin following the procedures set out in Article 
26(4). Where there is a hit, it shall transmit for all data sets corresponding to the hit 
the data referred to in Article 12, 13(2) and 14(2) along with, where appropriate, the 
mark referred to in Article 17(1) and (4). Where a negative hit result is received, the 
data referred to in Article 12, 13(2) and 14(2) shall not be transmitted. 
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(5) Where evidence of a hit is received by a Member State from Eurodac that can assist 
that Member State to carry out its obligations under Article 1(1 )(a), that evidence 
shall take precedence over any other hit received. 


* 603/2013 (adapted) 

CHAPTER M YI 


DATA 

STORAGE, ADVANCED DATA ERASURE AND MARKING OF 

DATA O 


Article ö 17 

Data storage 

1. E> For the purposes laid down in Article 10(1), <3 Eeach set of data [S> relating to an 
applicant for international protection <3 , as referred to in Article +4= 12, shall be stored in the 
Central System for ten years from the date on which the fingerprints were taken. 


-0- new 

2. For the purposes laid down in Article 13(1), each set of data relating to a third-country 
national or stateless person as referred to in Article 13(2) shall be stored in the Central System 
for live years from the date on which his or her fingerprints were taken. 

3. For the purposes laid down in Article 14(1), each set of data relating to a third-country 
national or stateless person as referred to in Article 14(2) shall be stored in the Central System 
for five years from the date on which his or her fingerprints were taken. 


* 603/2013 (adapted) 

■=> new 

34 . Upon expiry of the poriod E> data storage periods <3 referred to in paragraphs 1 O to 
3 O IE> of this Article <3 , the Central System shall automatically erase the data IE> of the 
data-subjects <3 from the Central System. 

Article 33 18 

Advnnee E> Advanced <3 data erasure 

1. Data relating to a person who has acquired citizenship of any Member State before expiry 
of the period referred to in Article 4347 (1) ■=> , (2) or (3) <=■ shall be erased from the Central 
System in accordance with Article 37 2S(4) as soon as the Member State of origin becomes 
aware that the person concemed has acquired such citizenship. 

2. The Central System shall, as soon as possible and no later than after 72 hours, inform all 
Member States of origin of the erasure of data in accordance with paragraph 1 by another 
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Member State of origin having produced a hit with data which they transmitted relating to 
persons referred to in Article g 10(1)* ©# M 11(1) ■=> or 14(1) <=■ . 

Article ö 19 

Marking of data 

1. For the purposes laid down in Article 1 (1 )(a), the Member State of origin which granted 
international protection to an applicant for international protection whose data were 
previously recorded in the Central System pursuant to Article ö 12 shall mark the relevant 
data in conformity with the requirements for electronic communication with the Central 
System established by E> eu-LISA <3 the Agcn ey. That mark shall be stored in the Central 
System in accordance with Article +2 17(1) for the purpose of transmission under Article 9(=5) 
O 15 O . The Central System shall O , as soon as possible and no later than 72 hours, O 
inform all Member States of origin of the marking of data by another Member State of origin 
having produced a hit with data which they transmitted relating to persons referred to in 
Article g JJ)(1)* ©# 4=411(1) O or 14(1) O . Those Member States of origin shall also mark the 
corresponding data sets. 

2. The data of beneficiaries of international protection stored in the Central System and 
marked pursuant to paragraph 1 of this Article shall be made available for comparison for the 
purposes laid down in Article l (5¥l)(c) for a period of three years after the date on which the 
data subject was granted international protection. 

Where there is a hit, the Central System shall transmit the data referred to in Article M 12fa4 
to (k) ■=> (b) to (s) ^ for all the data sets corresponding to the hit. The Central System shall 
not transmit the mark referred to in paragraph 1 of this Article. Upon the expiry of the period 
of three years, the Central System shall automatically block such data from being transmitted 
in the event of a request for comparison for the purposes laid down in Article 1^ (l)(c). 
whilst leaving those data available for comparison for the purposes laid down in Article 
l(l)ja) until the point of their erasure. Blocked data shall not be transmitted, and the Central 
System shall return a negative result to the requesting Member State in the event of a hit. 

3. The Member State of origin shall unmark or unblock data conceming a third-country 
national or stateless person whose data were previously marked or blocked in accordance with 
paragraphs 1 or 2 of this Article if his or her status is revoked or ended or the renewal of his 
or her status is refused under [Articles 14 or 19 of Directive 2011/95/EU]. 


-0- new 

4. For the purposes laid down in Article l(l)(b), the Member State of origin which 
granted a residence document to an illegally staying third-country national or stateless person 
whose data were previously recorded in the Central System pursuant to Article 13(2) and 
14(2) shall mark the relevant data in conformity with the requirements for electronic 
communication with the Central System established by eu-LISA. That mark shall be stored in 
the Central System in accordance with Article 17(2) and (3) for the purpose of transmission 
under Article 15 and 16. The Central System shall, as soon as possible and no later than 72- 
hours, inform all Member States of origin of the marking of data by another Member State of 
origin having produced a hit with data which they transmitted relating to persons referred to 
in Articles 13(1) or 14(1). Those Member States of origin shall also mark the corresponding 
data sets. 
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5. The data of illegally staying third-country nationals or stateless persons stored in the 
Central System and marked pursuant to paragraph 4 of this Article shall be made available for 
comparison for the purposes laid down in Article l(l)(c) until such data is automatically 
erased from the Central System in accordance with Article 17(4). 


* 603/2013 (adapted) 
■=> new 


CHAPTER VII 


PROCEDURE FOR COMPARISON AND DATA TRANSMISSION FOR 
LA W ENFORCEMENT PURPOSES 


Article ML 20 

Procedure for comparison of fingerprint data with Eurodac data 

1. For the purposes laid down in Article 1 42)1 1 )tc) . the designated authorities referred to in 
Articles # 6(1) and 7 8(2) may submit a reasoned electronic request as provided for in Article 
29 21(1) together with the reference number used by them, to the verifying authority for the 
transmission for comparison of fingerprint O and facial image O data to the Central System 
via the National Access Point. Upon receipt of such a request, the verifying authority shall 
verify whether all the conditions for requesting a comparison referred to in Articles 20 21 or 
24= 22. as appropriate, are fulfilled. 

2. Where all the conditions for requesting a comparison referred to in Articles 20 21 or 24= 22 
are fulfilled, the verifying authority shall transmit the request for comparison to the National 
Access Point which will process it to the Central System in accordance with Articles 9(3) and 

■=> 15 and 16 O for the purpose of comparison with the E> fingerprint <3 ■=> and facial 
image <=■ data transmitted to the Central System pursuant to Articles 9 10( 1), and 44 13(2) 
0(1) and 14(1)0. 


ff new 

3. A comparison of a facial image with other facial image data in the Central System 
pursuant to Article l(l)(c) may be carried out in accordance with Article 16(1), if such data is 
available at the time the reasoned electronic request is made pursuant to Article 21(1). 


* 603/2013 (adapted) 

O new 

M- In exceptional cases of urgency where there is a need to prevent an imminent danger 
associated with a terrorist offence or other serious criminal offence, the verifying authority 
may transmit the fingerprint data to the National Access Point for comparison immediately 
upon receipt of a request by a designated authority and only verify ex-post whether all the 
conditions for requesting a comparison referred to in Article ^ 21 or Article ö 22 are 
fulfilled, including whether an exceptional case of urgency actually existed. The ex-post 
verification shall take place without undue delay after the processing of the request. 
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45 . Where an ex-post verification determines that the access to Eurodac data was not justified, 
all the authorities that have accessed such data shall erase the information communicated from 
Eurodac and shall inform the verifying authority of such erasure. 

Article ^ 21 

Conditions for access to Eurodac by designated authorities 

1. For the purposes laid down in Article l tS¥l¥c). designated authorities may submit a 
reasoned electronic request for the comparison of fingerprint data with the data stored in the 
Central System within the scope of their powers only if comparisons with the following 
databases did not lead to the establishment of the identity of the data subject: 

- national fingerprint databases; 

the automated fingerprinting Identification Systems of all other Member States under 
Decision 2008/615/JHA where comparisons are technically available, unless there 
are reasonable grounds to believe that a comparison with such Systems would not 
lead to the establishment of the identity of the data subject. Such reasonable grounds 
shall be included in the reasoned electronic request for comparison with Eurodac 
data sent by the designated authority to the verifying authority; and 

the Visa Infonnation System provided that the conditions for such a comparison laid 
down in Decision 2008/633/JHA are met; 

and where the following cumulative conditions are met: 

(a) the comparison is necessary for the purpose of the prevention, detection or 
investigation of terrorist offences or of other serious criminal offences, which means 
that there is an overriding public security concern which makes the searching of the 
database proportionate; 

(b) the comparison is necessary in a specific case (i.e. systematic comparisons shall 
not be carried out); and 

(c) there are reasonable grounds to consider that the comparison will substantially 
contribute to the prevention, detection or investigation of any of the criminal 
offences in question. Such reasonable grounds exist in particular where there is a 
substantiated suspicion that the suspect, perpetrator or victim of a terrorist offence or 
other serious criminal offence falls in a category covered by this Regulation. 

2. Requests for comparison with Eurodac data shall be limited to searching with fingerprint 
O or facial image O data. 


Article 24= 22 

Conditions for access to Eurodac by Europol 

1. For the purposes laid down in Article l £3¥l¥c) . Europol's designated authority may submit 
a reasoned electronic request for the comparison of fingerprint data with the data stored in the 
Central System within the limits of Europol’s mandate and where necessary for the 
perfonnance of Europol’s tasks only if comparisons with fingerprint data stored in any 
infonnation processing Systems that are technically and legally accessible by Europol did not 
lead to the establishment of the identity of the data subject and where the following 
cumulative conditions are met: 
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(a) the comparison is necessary to support and strengthen action by Member States in 
preventing, detecting or investigating terrorist offences or other serious criminal 
offences falling under Europol’s mandate, which means that there is an overriding 
public security concern which makes the searching of the database proportionate; 

(b) the comparison is necessary in a specific case (i.e. systematic comparisons shall 
not be carried out); and 

(c) there are reasonable grounds to consider that the comparison will substantially 
contribute to the prevention, detection or investigation of any of the criminal 
offences in question. Such reasonable grounds exist in particular where there is a 
substantiated suspicion that the suspect, perpetrator or victim of a terrorist offence or 
other serious criminal offence falls in a category covered by this Regulation. 

2. Requests for comparison with Eurodac data shall be limited to comparisons of fingerprint 
O and facial image O data. 

3. Processing of information obtained by Europol from comparison with Eurodac data shall be 
subject to the authorisation of the Member State of origin. Such authorisation shall be 
obtained via the Europol national unit of that Member State. 

Article 44 23 

Communication between the designated authorities, the verifying authorities and the 

National Access Points 

1. Without prejudice to Article M 22, all communication between the designated authorities, 
the verifying authorities and the National Access Points shall be secure and take place 
electronically. 

2. For the purposes laid down in Article l f3¥14(c) . fmgerprints shall be digitally processed by 
the Member States and transmitted in the data format roforrod to E> as set out <3 in O the 
agreed Interface Control Document <=> Annex I , in order to ensure that the comparison can be 
carried out by means of the computerised fingerprint recognition system. 

CHAPTER VIII 


DATA PROCESSING, DATA PROTECTIONANDLIABILITY 

Article M 24 

Responsibility for data processing 

1. The Member State of origin shall be responsible for ensuring that: 

(a) fmgerprints O and facial images <=■ are taken lawfully; 

(b) fingerprint data and the other data referred to in Article 44= |2, Article 44 13(2) 
and Article 44 14(2) are lawfully transmitted to the Central System; 

(c) data are accurate and up-to-date when they are transmitted to the Central System; 

(d) without prejudice to the responsibilities of IS> eu-LISA <3 the Agoncy , data in 
the Central System are lawfully recorded, stored, corrected and erased; 

(e) the results of fingerprint O and facial image O data comparisons transmitted by 
the Central System are lawfully processed. 
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2. In accordance with Article M M, the Member State of origin shall ensure the security of 
the data referred to in paragraph 1 before and during transmission to the Central System as 
well as the security of the data it receives from the Central System. 

3. The Member State of origin shall be responsible for the linal identification of the data 
pursuant to Article M 26(4). 

4. The Agoncy [S> eu-LISA <3 shall ensure that the Central System is operated in accordance 
with the provisions of this Regulation. In particular, the Agcn ey E> eu-LISA <3 shall: 

(a) adopt measures ensuring that persons working with the Central System process 
the data recorded therein only in accordance with the purposes of Eurodac as laid 
down in Article 1; 

(b) take the necessary measures to ensure the security of the Central System in 
accordance with Article M Mi 

(c) ensure that only persons authorised to work with the Central System have access 
thereto, without prejudice to the competences of the European Data Protection 
Supervisor. 

The Agoncy IE> eu-LISA <3 shall inform the European Parliament and the Council as well as 
the European Data Protection Supervisor of the measures it takes pursuant to the first 
subparagraph. 


Article £4 25 

Transmission 

1. Fingerprints shall be digitally processed and transmitted in the data fonnat referred t # 
1E> as set out <3 in A the agreed Interface Control Document O Annex I . As far as necessary 
for the efficiënt operation of the Central System, the Agcn ey E> eu-LISA 31 shall establish 
the technical requirements for transmission of the data fonnat by Member States to the 
Central System and vice versa. The Agcn ey E> eu-LISA 31 shall ensure that the fingerprint 
data O and facial images <p transmitted by the Member States can be compared by the 
computerised fingerprint O and facial <=> recognition system. 

2. Member States shall transmit the data referred to in Article tfc 12, Article L4 13(2) and 
Article ö 14(2) electronically. The data referred to in Article 12* Article M 13(2) 
O and Article 14(2) O shall be automatically recorded in the Central System. As far as 
necessary for the efficiënt operation of the Central System, the Agen oy [3> eu-LISA 31 shall 
establish the technical requirements to ensure that data can be properly electronically 
transmitted from the Member States to the Central System and vice versa. 

3. The reference number referred to in Articles 1 l(d) 12(0 . 11(2)(d) 13(2)(i), W 14rt4 
O (2)(i) <=■ and W 20(1) shall make it possible to relate data unambiguously to one particular 
person and to the Member State which is transmitting the data. In addition, it shall make it 
possible to teil whether such data relate to a person referred to in Article g JJ)(T)> M MO) or 

öI4(l)- 

4. The reference number shall begin with the identification letter or letters by whichf=4n 
accordance with the norm referred to in Annex I, the Member State transmitting the data is 
identified. The identification letter or letters shall be followed by the identification of the 
category of person or request. "1" refers to data relating to persons referred to in Article g 
10( 1). "2" to persons referred to in Article M MO)* "3" to persons referred to in Article L? 
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14(1), "4" to requests referred to in Article 29 21, "5" to requests referred to in Article 24= 22 
and "9" to requests referred to in Article 29 30. 

5. The Agcn ey E> eu-LISA <3 shall establish the technical procedures necessary for Member 
States to ensure receipt of unambiguous data by the Central System. 

6 The Central System shall confinn receipt of the transmitted data as soon as possible. To that 
end, the Agoncy E> eu-LISA <3 shall establish the necessary technical requirements to 
ensure that Member States receive the confinnation receipt if requested. 

Article ^ 26 

Carrying out comparisons and transmitting results 

1. Member States shall ensure the transmission of fingerprint data of an appropriate quality 
for the purpose of comparison by means of the computerised fingerprint O and facial O 
recognition system. As far as necessary to ensure that the results of the comparison by the 
Central System reach a very high level of accuracy, the Agcn ey [S> eu-LISA <3 shall define 
the appropriate quality of transmitted fingerprint data. The Central System shall, as soon as 
possible, check the quality of the fingerprint O and facial image O data transmitted. If 
fingerprint O or facial image O data do not lend themselves to comparison using the 
computerised fingerprint O and facial O recognition system, the Central System shall inform 
the Member State concerned. That Member State shall then transmit fingerprint O or facial 
image O data of the appropriate quality using the same reference number as the previous set 
of fingerprint O or facial image <=■ data. 

2. The Central System shall carry out comparisons in the order of arrival of requests. Each 
request shall be dealt with within 24 hours. A Member State may for reasons connected with 
national law require particularly urgent comparisons to be carried out within one hour. Where 
such time-limits cannot be respected owing to circumstances which are outside the Agoncy's 
E> eu-LISA's <3 responsibility, the Central System shall process the request as a matter of 
priority as soon as those circumstances no longer prevail. In such cases, as far as is necessary 
for the efficiënt operation of the Central System, the Agoncy E> eu-LISA <3 shall establish 
criteria to ensure the priority handling of requests. 

3. As far as necessary for the efficiënt operation of the Central System, the Agoncy [H> eu- 
LISA <3 shall establish the operational procedures for the processing of the data received and 
for transmitting the result of the comparison. 

4. The result of the comparison E> of fingerprint data carried out pursuant to Article 15 <3 
shall be immediately checked in the receiving Member State by a fingerprint expert as defined 
in accordance with its national rules, specifically trained in the types of fingerprint 
comparisons provided for in this Regulation. For the purposes laid down in Article l(l)(a) 
and (b) of this Regulation, final identification shall be made by the Member State of origin in 
cooperation with the other Member States concerned , pursuant to Article 31 of Regulation 
(EU) No 601/2013 . 


-0- new 

5. The result of the comparison of facial image data carried out pursuant to Article 16 
shall be immediately checked and verified in the receiving Member State. For the purposes 
laid down in Article l(l)(a) and (b) of this Regulation, final identification shall be made by 
the Member State of origin in cooperation with the other Member States concerned. 
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* 603/2013 (adapted) 

■=> new 

Information received from the Central System relating to other data found to be unreliable 
shall be erased as soon as the unrebability of the data is established. 


M- Where final identification in accordance with paragraph 4 reveals that the result of the 
comparison received from the Central System does not correspond to the lingcrprint O or 


facial image O data sent for comparison, Member States shall immediately erase the result of 
the comparison and communicate this fact as soon as possible and no later than after three 
working days to the Commission and to E> eu-LISA <3 the Agen #y O and infonn them of 
the reference number of the Member State of origin and the reference number of the Member 
State that received the result <7 . 


Article 27 

Communication between Member States and the Central System 

Data transmitted from the Member States to the Central System and vice versa shall use the 
Communication Infrastructure. As far as is necessary for the efficiënt operation of the Central 
System, the Agoncy [S> eu-LISA <3 shall establish the technical procedures necessary for the 
use of the Communication Infrastructure. 


Article 27 28 


Access to, and correction or erasure of, data recorded in Eurodac 


1. The Member State of origin shall have access to data which it has transmitted and which 
are recorded in the Central System in accordance with this Regulation. 


No Member State may conduct searches of the data transmitted by another Member State, nor 
may it receive such data apart from data resulting from the comparison referred to in Article 


15 and 16 O 


2. The authorities of Member States which, pursuant to paragraph 1 of this Article, have 
access to data recorded in the Central System shall be those designated by each Member State 
for the purposes laid down in Article ltll tal and tb) . That designation shall specify the exact 
unit responsible for carrying out tasks related to the application of this Regulation. Each 
Member State shall without delay communicate to the Commission and the Agcn ey E> eu- 
LISA <3 a list of those units and any amendments thereto. The Agoncy E> eu-LISA <3 shall 
publish the Consolidated list in the Official Journal of the European Union. Where there are 
amendments thereto, the Agoncy E> eu-LISA <3 shall publish once a year an updated 
Consolidated list online. 


3. Only the Member State of origin shall have the right to amend the data which it has 
transmitted to the Central System by correcting or supplementing such data, or to erase them, 
without prejudice to erasure carried out in pursuance of Article ■=> 18 <=■ 12(2) or 16(1) . 

4. If a Member State or the Agcn ey E> eu-LISA <3 has evidence to suggest that data 
recorded in the Central System are factually inaccurate, it shall O , without prejudice to the 
notification of a personal data breach pursuant to Article [33..] of Regulation (EU) No 
[.. 72016], <7 advise the Member State of origin as soon as possible. 
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If a Member State has evidence to suggest that data were recorded in the Central System in 
breach of this Regulation, it shall advise E> eu-LISA <3 the Agcncy , the Commission and 
the Member State of origin as soon as possible. The Member State of origin shall check the 
data concerned and, if necessary, amend or erase them without delay. 

5. The Agcn ey E> eu-LISA <3 shall not transfer or make available to the authorities of any 
third country data recorded in the Central System. This prohibition shall not apply to transfers 
of such data to third countries to which Regulation (EU) No [.../.. .] 604/20 44 applies. 


Article 2S 29 


Keeping of records 

1. The Agcncy E> eu-LISA <3 shall keep records of all data processing operations within the 
Central System. These records shall show the purpose, date and time of access, the data 
transmitted, the data used for interrogation and the name of both the unit entering or retrieving 
the data and the persons responsible. 


2. The records referred to in paragraph 1 of this Article may be used only for the data 
protection monitoring of the admissibility of data processing as well as to ensure data security 
pursuant to Article 34. The records must be protected by appropriate measures against 
unauthorised access and erased after a period of one year after the storage period referred to in 
Article O 17 <=■ 12(1) and in Article 16(1) has expired, unless they are required for 


monitoring procedures which have already begun. 


3. For the purposes laid down in Article 1 (1 ) (a) and (b) . each Member State shall take the 
necessary measures in order to achieve the objectives set out in paragraphs 1 and 2 of this 
Article in relation to its national system. In addition, each Member State shall keep records of 
the staff duly authorised to enter or retrieve the data. 


Article 29 30 


Rights \E> of information <3 of the data subject 

1. A person covered by Article g 10(1). Article M 13(1) or Article ö 14(1) shall be informed 
by the Member State of origin in writing, and where necessary, orally, in a language that he or 
she understands or is reasonably supposed to understand O in a concise, transparent, 
intelligible and easily accessible form, using clear and plain language O , of the following: 


(a) the identity of the controller within the meaning of Article 2(4) of Directive 
[../■■/EUJ 95/ 4 6/EC and of his or her representative, if any O and the contact details of 
the data protection officer O ; 


(b) the purpose for which his or her data will be processed in Eurodac, including a 
description of the aims of Regulation (EU) No [.../...] 601/2013 , in accordance with 
O Article 6 O thereof and an explanation in intelligible form ? using clear and plain 
language, of the fact that Eurodac may be accessed by the Member States and 
Europol for law enforcement purposes; 


(c) the recipients O or categories of recipients O of the data; 


(d) in relation to a person covered by Article g JJ)(1) or M 13(1) O or 14(1) <p 
obligation to have his or her fingerprints taken; 


the 
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3 new 

(e) the period for which the data will be stored pursuant to Article 17; 


* 603/2013 (adapted) 

■=> new 

(ff) E> the existence of <3 the right O to request from the controller O #f access to 
data relating to him or her, and the right to request that inaccurate data relating to 
him or her be corrcctcd [S> rectified <3 O and the completion of incomplete 
personal data <=> or that unlawfully processed E> personal <3 data relating t# 
E> conceming <3 him or her be erased or restricted, as well as the right to receive 
information on the procedures for exercising those rights including the contact details 
of the controller and the national supervisory authorities referred to in Article èê 

mm 


13 new 


(g) the right to lodge a complaint to the supervisory authority. 


* 603/2013 (adapted) 

==> new 

2. In relation to a person covered by Article g M(l) or M 13(1) O and 14(1) O , the 
information referred to in paragraph 1 of this Article shall be provided at the time when his or 
her fingerprints are taken. 

In relation to a person covered by Article 17(1), the information referred to in paragraph 1 of 
this Article shall be provided no later than at the time when the data relating to that person a re 
transmittcd to the Central System. That obligation shall not apply whcro the provi‘.ion of such 
information provco impoooiblc or would involvc a dioproportionate efforU 

Where a person covered by Article g JJ)(1), Article M 13(1) and Article ö M(l) is a minor, 
Member States shall provide the information in an age-appropriate marnier. 

3. A common leaflet, containing at least the information referred to in paragraph 1 of this 
Article and the information referred to in O Article 6(2) Oof Regulation (EU) No [.../...] 
601/2013 shall be drawn up in accordance with the procedure referred to in Article 44(2) of 
that Regulation. 

The leaflet shall be clear and simple, drafted O in a concise, transparent, intelligible and 
easily accessible fonn and O in a language that the person concerned understands or is 
reasonably supposed to understand. 

The leaflet shall be established in such a marnier as to enable Member States to complete it 
with additional Member State-specific information. This Member State-specific information 
shall include at least the rights of the data subject, the possibility of assistanco 
O information <=■ by the national supervisory authorities, as well as the contact details of the 
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office of the controller O and of the data protection officer, O and the national supervisory 
authorities. 


Article 31 

\E> Right of access to, rectification and erasure of personal data <3 

41 . For the purposes laid down in Article 1 f 1 f f af and tb) of this Regulation, in cach Mcmbcr 
State any data subject may, in accordance with the lawo, regulationo and procedures of that 
State, cxcrcisc the rights providcd for in Articlc 12 of Dircctivc 95/46/EG ■=> the data subjecfs 
rights of access, rectification and erasure shall be exercised in accordance ,with Chapter III of 
Regulation (EU) No. [.. ./2016] and applied as set out in this Article <=■ . 

Without projudico to the obligation to provido othor information in accordanco with Articlo 
12(a) of Dircctivc 95/46/E U? IE> 2. The right of access of <3 the data subject [S> in each 
Mernber State <3 shall havo E> include <3 the right to obtain communication of the data 
relating to him or her recorded in the Central System and of the Mernber State which 
transmitted them to the Central System. Such access to data may be granted only by a 
Mernber State. 

5. For the purposes laid down in Article 1(1), in each Member State, any person may request 
that data which are factually inaccurate bc corrcctcd or that data rccordcd unlawfully 
erased. The correction and erasure shall be carried out without exceooive delay by the Member 
State which transmitted the data, in accordance with its laws, regulations and procedures. 

62 . For the purposos laid down in Articlo 1(1), j[f the rights of correction [H> rectification <3 
and erasure are exercised in a Member State other than that, or those, which transmitted the 
data, the authorities of that Member State shall contact the authorities of the Member State or 
States which transmitted the data so that the latter may check the accuracy of the data and the 
lawfulness of their transmission and recording in the Central System. 

43 . For the purposcs laid down in Articlc 1(1), jlf it emerges that data recorded in the Central 
System are factually inaccurate or have been recorded unlawfully, the Member State which 
transmitted them shall correct E> rectify <3 or erase the data in accordance with Article 
28(3). That Member State shall confirm in writing to the data subject without oxcosoivo delay 
that it has taken action to correct E> , rectify, <3 ■=> complete, <p m erase O or restrict the 
processing of <=■ I5> personal <3 data relating to him or her. 

84 . For the purposcs laid down in Articlc 1(1), jlf the Member State which transmitted the 
data does not agree that data recorded in the Central System are factually inaccurate or have 
been recorded unlawfully, it shall explain in writing to the data subject without exceooive 
delay why it is not prepared to correct or erase the data. 

That Member State shall also provide the data subject with information explaining the steps 
which he or she can take if he or she does not accept the explanation provided. This shall 
include infonnation on how to bring an action or, if appropriate, a complaint before the 
competent authorities or courts of that Member State and any financial or other assistance that 
is available in accordance with the laws, regulations and procedures of that Member State. 

45 . Any request under paragraphs 4 1 and § 2 of this Article for access, rectification or 
erasure <3 shall contain all the necessary particulars to identify the data subject, including 
fingerprints. Such data shall be used exclusively to perrnit the exercise of the E> data 
subjecfs <3 rights referred to in paragraphs 4 1 and § 2 and shall be erased immediately 
afterwards. 
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446 . The competent authorities of the Member States shall cooperate actively to enforce 
promptly the IE> data subject's <3 rights laid down in paragraphs 5, 6 and 7 E> for 
rectification and erasure <3 . 

4=4=7 . Whenever a person requests E> access to <3 data relating to him or her in accordancc 
with paragraph 4 , the competent authority shall keep a record in the form of a written 
document that such a request was made and how it was addressed, and shall make that 
document available to the national supervisory authorities without delay. 

12. For the purposcs laid down in Articlo 1(1) of this Rogulation, in cach Momber State, the 

national supervisory authority shall, on the basis of his or her request, assist the data subjcct 4n 

accordancc with Articlc 28(4) of Dircctivc 95/46/EC in cxercioing his or her rights. 

4A8 . For the purposcs laid down in Articlc 1(1) of this Rcgulation, |Xhe national supervisory 
authority of the Member State which transmitted the data and the national supervisory 
authority of the Member State in which the data subject is present shall assist and , where 
requested, adviso him or hor in oxorcising E> provide infomiation to the data subject 
conceming the exercise of <3 his or her right to O request from the data controller access, <=■ 
correct \E> rectification, <3 ■=> completion, <=■ or erasc 1S> erasure <3 ■=> or restriction of the 
processing of O E> personal <3 data \E> concerning him or her <E1 . Both nationa 
E> The <3 supervisory authorities shall cooperate to this end ■=> in accordance with Chapter 
VII of Regulation (EU) [.../2016] <p . R-cqucsts for such assistancc may bc made to the 
national supervisory authority of the Member State in which the data subject is present, which 

shall transmit the requests to the authority of the Member State which transmitted the data. 

14. In cach Member State any person may, in accordancc with the laws, rcgulations and 

procedures of that State, bring an action or, if appropriatc, a complaint before the competent 

courts of the State if hc or she is rotU . 1 the right of access pnm d od for in 

paragraph 4. 

15. Any person may, in accordancc with the laws, rogulations and procedures of the Member 

State which transmitted the data, bring an action or, if appropriatc, a complaint before the 

competent authorities or courts of that State concerning the data relating to him or her 

rccordcd in the Central System, in order to exercise his or her rights undcr paragraph 5. T he 

#bfiga4#M4==#j=# ^ national gupendscry nim th e ritiet; to assist a #d, w here requested, advise t h # 
data subject in accordance with paragraph 13 shall subsist throughout the procccdings. 


Article Ml 32 


Supervision by the national supervisory authorities 

1. For the purposcs laid down in Articlo 1(1) of this Rcgulation, each Member State shall 
provide that |The national supervisory authority or authorities E> of each Member State <3 
designated pursuant to Article => 41 <p 28(1) of Directive 95/4 6/EC ■=> referred to in Article 
[46(1)] of Regulation (EU) [.../2016] O shall monitor independently, in accordance with its 
rospcctivo national law, the lawfulness of the processingf in accordancc with this Rcgulation, 
of personal data by the Member State in question E> for the purposes laid out in Article 
1(1 )(a) and (b) <3 , including their transmission to the Central System. 


2. Each Member State shall ensure that its national supervisory authority has access to advice 
from persons with sufficiënt knowledge of fingerprint data. 


Article 34= 33 

Supervision by the European Data Protection Supervisor 
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1. The European Data Protection Supervisor shall ensure that all the personal data processing 
activities concerning Eurodac, in particular by E> eu-LISA <3 the Agoncy , are carried out in 
accordance with Regulation (EC) No 45/2001 and with this Regulation. 

2. The European Data Protection Supervisor shall ensure that an audit of the Agoncy's E> eu- 
LISA's <3 personal data processing activities is carried out in accordance with international 
auditing standards at least every three years. A report of such audit shall be sent to the 
European Parliament, the Council, the Commission, E> eu-LISA <3 the Agcn ey, and the 
national supervisory authorities. The Agoncy E> eu-LISA <3 shall be given an opportunity to 
make comments before the report is adopted. 

Article ££ 34 

Cooperation between national supervisory authorities and the European Data 

Protection Supervisor 

1. The national supervisory authorities and the European Data Protection Supervisor shall, 
each acting within the scope of their respective competences, cooperate actively in the 
framework of their responsibilities and shall ensure coordinated supervision of Eurodac. 

2. Member States shall ensure that every year an audit of the processing of personal data for 
the purposes laid down in Article l tSdVc) is carried out by an independent body, in 
accordance with Article 33121 35111. including an analysis of a sample of reasoned electronic 
requests. 

The audit shall be attached to the annual report of the Member States referred to in Article 
mm 42181 . 

3. The national supervisory authorities and the European Data Protection Supervisor shall, 
each acting within the scope of their respective competences, exchange relevant infonnation, 
assist each other in carrying out audits and inspections, examine diffïculties of interpretation 
or application of this Regulation, study problems with the exercise of independent supervision 
or in the exercise of the rights of data subjects, draw up harmonised proposals for joint 
Solutions to any problems and promote awareness of data protection rights, as necessary. 

4. For the purpose laid down in paragraph 3, the national supervisory authorities and the 
European Data Protection Supervisor shall meet at least twice a year. The costs and servicing 
of these meetings shall be for the account of the European Data Protection Supervisor. Rules 
of procedure shall be adopted at the flrst meeting. Further working methods shall be 
developed jointly as necessary. A joint report of activities shall be sent to the European 
Parliament, the Council, the Commission and the Agoncy E> eu-LISA <3 every two years. 

Article 33 343. 

Protection of personal data for law enforcement purposes 

1. Each Member State ohall provide that the provioions adopted under national law 
implomonting Framework Docision 2008/977/JHA are also applicablo to the processing of 
porsoi ted=ëk ria by its national authorities for the purposes laid down in Article 1(2) of this 
Regulation. 

34 . The IS> supervisory authority or authorities of each Member State referred to in Article 
[39(1)] ofDirective [2016/... /EU] shall <3 monitormg ©fthe lawfulness of the processing of 
personal data under this Regulation by the Member States for the purposes laid down in 
Article l (Sl) (c) of this Regulation, including their transmission to and from Eurodac? shall be 
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carricd out by the national supervisory authoritics designated pursuant to Framewe rk 

Decision 2008/977/JHA . 

3=2 . The processing of personal data by Europol pursuant to this Regulation shall be in 
accordance with Decision 2009/371/JHA and shall be supervised by an independent extemal 
data protection supervisor. Articles 30, 31 and 32 of that Decision shall be applicable to the 
processing of personal data by Europol pursuant to this Regulation. The independent extemal 
data protection supervisor shall ensure that the rights of the individual are not violated. 

43 . Personal data obtained pursuant to this Regulation from Eurodac for the purposes laid 
down in Article 1 (21 )(c) shall only be processed for the purposes of the prevention, detection 
or investigation of the specific case for which the data have been requested by a Member 
State or by Europol. 

M. E> Without prejudice to Article [23 and 24] of Directive [2016/ .../ELI], <3 Tthc Central 
System, the designated and verifying authorities and Europol shall keep records of the 
searches for the purpose of permitting the national data protection authorities and the 
European Data Protection Supervisor to monitor the compliance of data processing with 
Union data protection mies, including for the purpose of maintaining records in order to 
prepare the annual reports referred to in Article 40171 42181 . Other than for such purposes, 
personal data, as well as the records of the searches, shall be erased in all national and 
Europol files after a period of one month, unless the data are required for the purposes of the 
specific ongoing criminal investigation for which they were requested by a Member State or 
by Europol. 


Article £4 36 

Data security 

1. The Member State of origin shall ensure the security of the data before and during 
transmission to the Central System. 

2. Each Member State shall, in relation to all data processed by its competent authorities 
pursuant to this Regulation, adopt the necessary measures, including a security plan, in order 
to: 

(a) physically protect the data, including by making contingency plans for the 
protection of critical infrastructure; 

(b) deny unauthorised persons access to ■=> data-processing equipment and O 
national installations in which the Member State carries out operations in accordance 
with the purposes of Eurodac ( O equipment, access control and O checks at 
entrance to the installation); 

(c) prevent the unauthorised reading, copying, modification or removal of data media 
(data media control); 

(d) prevent the unauthorised input of data and the unauthorised inspection, 
modification or erasure of stored personal data (storage control); 


-0- new 

(e) prevent the use of automated data-processing Systems by unauthorized persons 
using data communication equipment (user control); 
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* 603/2013 (adapted) _ 

(§D prevent the unauthorised processing of data in Eurodac and any unauthorised 
modification or erasure of data processed in Eurodac (control of data entry); 

(fg) ensure that persons authorised to access Eurodac have access only to the data 
covered by their access authorisation, by means of individual and unique user IDs 
and confidential access modes only (data access control); 

(gh) ensure that all authorities with a right of access to Eurodac create prolilcs 
describing the functions and responsibilities of persons who are authorised to access, 
enter, update, erase and search the data, and make those profiles and any other 
relevant infonnation which those authorities may require for supervisory purposes 
available to the national supervisory authorities referred to in E> Chapter VI of of 
Regulation (ELI) No. [.../2016] <3 Article 28 of Directive 95/ 4 6/EC ] and in 
IE> Chapter VI ofArticle of Directive [2016/.../EU] <3 IE> Article [..] of Directive 
[2016/.../EU] <3 2^ of Framcwork Dccisi os 2008/977/JHA without delay at their 
request (personnel profiles); 

(hi) ensure that it is possible to verify and establish to which bodies personal data 
may be transmitted using data communication equipment (communication control); 

(Ü) ensure that it is possible to verify and establish what data have been processed in 
Eurodac, when, by whom and for what purpose (control of data recording); 

(|k) prevent the unauthorised reading, copying, modification or erasure 
E> deletion <3 of personal data during the transmission of personal data to or from 
Eurodac or during the transport of data media, in particular by means of appropriate 
encryption techniques (transport control); 


-0- new 

(l) ensure that installed Systems may, in case of interruption, be restored (recovery); 

(m) ensure that the functions of Eurodac perfonn, that the appearance of faults in the 
functions is reported (reliability) and that stored personal data cannot be corrupted by 
means of malfunctioning of the System (integrity); 


* 603/2013 (adapted) 

O new 

(kn ) monitor the effectiveness of the security measures referred to in this paragraph 
and take the necessary organisational measures related to intemal monitoring in order 
to ensure compliance with this Regulation (self-auditing) and to automatically detect 
within 24 hours any relevant events arising from the application of measures listed in 
points (b) to 0 ^ (k) <=> that might indicate the occurrence of a security incident. 

3. Member States shall inform the Agcn ey E> eu-LISA <3 of security incidents detected on 
their Systems O without prejudice to the notification and communication of a personal data 
breach pursuant to [Articles 31 and 32] of Regulation (EU) No [.../2016] respectively 
[Articles 28 and 29] O . The Agoncy IS> eu-LISA <3 shall inform the Member States, 
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Europol and the European Data Protection Supervisor in case of security incidents. The 
Member States concerned, the Agoncy E> eu-LISA <3 and Europol shall collaborate during a 
security incident. 

4. The Agoncy E> eu-LISA <3 shall take the necessary measures in order to achieve the 
objectives set out in paragraph 2 as regards the operation of Eurodac, including the adoption 
of a security plan. 


Article M 37 

Prohibition of transfers of data to third countries, international organisations or private 

entities 

1. Personal data obtained by a Member State or Europol pursuant to this Regulation from the 
Central System shall not be transferred or made available to any third country, international 
organisation or private entity established in or outside the Union. This prohibition shall also 
apply if those data are further processed at national level or between Member States within 
the meaning of [Article [...]3(¥) of Directive [2016/../EU] Framowork — Docision 
2008/977/JHA ]. 

2. Personal data which originated in a Member State and are exchanged between Member 
States following a hit obtained for the purposes laid down in Article l (S¥l)(c) shall not be 
transferred to third countries if there is a sorioiis E> real <3 risk that as a result of such 
transfer the data subject may be subjected to torture, inhuman and degrading treatment or 
punishment or any other violation of his or her fundamental rights. 


-0- new 

3. No Information regarding the fact that an application for international protection has 
been made in a Member State shall be disclosed to any third-country for persons related to 
Article 10(1), particularly where that country is also the applicanfs country of origin. 


* 603/2013 (adapted) 

O new 

34 . The prohibitions referred to in paragraphs 1 and 2 shall be without prejudice to the right of 
Member States to transfer such data O in accordance with Chapter V of Regulation (EU) No 
[.../2016] respectively with the national rules adopted pursuant to Directive [2016/.../EU] <=■ 
to third countries to which Regulation (EU) No [.../...] 601/2013 applies. 


-0- new 

Article 38 

Transfer of data to third countries for the purpose of return 

1. By way of derogation from Article 37 of this Regulation, the personal data relating to 
persons referred to in Articles 10(1), 13(2), 14(1) obtained by a Member State following a hit 
for the purposes laid down in Article 1(1 )(a) or (b) may be transferred or made available to a 
third-country in accordance with Article 46 of Regulation (EU) No. [.../2016], if necessary in 
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order to prove the identity of third-country nationals for the purpose of return, only where the 
following conditions are satisfied: 

(b) the third country explicitly agrees to use the data only for the purpose for which they 
were provided and to what is lawful and necessary to secure the purposes laid down in Article 
1(1 )(b) and to delete that data where it is no longer justified to keep it; 

(c) the Member State of origin which entered the data in the Central System has given its 
consent and the individual concerned has been informed that his or her personal information 
may be shared with the authorities of a third-country. 

2. No Information regarding the fact that an application for international protection has 
been made in a Member State shall be disclosed to any third-country for persons related to 
Article 10(1), particularly where that country is also the applicanfs country of origin. 

3. A third-country shall not have direct access to the Central System to compare or 
transmit (ingcrprint data or any other personal data of a third-country national or stateless 
person and shall not be granted access via a Member State's designated National Access 
Point. 


* 603/2013 (adapted) 
■=> new 


Article 34 39 

Logging and documentation 

1. Each Member State and Europol shall ensure that all data processing operations resulting 
from requests for comparison with Eurodac data for the purposes laid down in Article 
1 ( 24(1 )(c) are logged or documented for the purposes of checking the admissibility of the 
request, monitoring the lawfulness of the data processing and data integrity and security, and 
self-monitoring. 

2. The log or documentation shall show in all cases: 

(a) the exact purpose of the request for comparison, including the concemed form of 
a terrorist offence or other serious criminal offence and, for Europol, the exact 
purpose of the request for comparison; 

(b) the reasonable grounds given not to conduct comparisons with other Member 
States under Decision 2008/615/JHA, in accordance with Article ^ 21(1) of this 
Regulation; 

(c) the national file reference; 

(d) the date and exact time of the request for comparison by the National Access 
Point to the Central System; 

(e) the name of the authority having requested access for comparison, and the person 
responsible who made the request and processed the data; 

(f) where applicable, the use of the urgent procedure referred to in Article 19(3) 
20(4) and the decision taken with regard to the ex-post verification; 

(g) the data used for comparison; 
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(h) in accordance with national rules or with Decision 2009/371/JHA, the identifying 
mark of the official who carried out the search and of the official who ordered the 
search or supply. 

3. Logs and documentation shall be used only for monitoring the lawfulness of data 
processing and for ensuring data integrity and security. Only logs E> which do not <3 
containiftg non personal data may be used for the monitoring and evaluation referred to in 
Article ^ 42. The competent national supervisory authorities responsible for checking the 
admissibility of the request and monitoring the lawfulness of the data processing and data 
integrity and security shall have access to these logs at their request for the purpose of 
fuffilling their dutios E> tasks <3 . 


Article ö 40 

Liability 

1. Any person who, or Member State which, has suffered E> material or immaterial <3 
damage as a result of an unlawful processing operation or any act incompatible with this 
Regulation shall be entitled to receive compensation from the Member State responsible for 
the damage suffered. That State shall be exempted from its liability, in whole or in part, if it 
proves that it is not 1E> in any way <3 responsible for the event giving rise to the damage. 

2. If the failure of a Member State to comply with its obligations under this Regulation causes 
damage to the Central System, that Member State shall be liable for such damage, unless and 
insofar as the Agoncy 1E> eu-LISA <3 or another Member State failed to take reasonable 
steps to prevent the damage from occurring or to minimise its impact. 

3. Claims for compensation against a Member State for the damage referred to in paragraphs 
1 and 2 shall be governed by the provisions of national law of the defendant Member State 
■=> in accordance with Articles [75 and 76] of Regulation (EU) [.../2016] and Articles [52 and 
53] of Directive [2016/... /EU] <=■ . 

CHAPTER VIII 


AMENDMENTS TO REGULATION (EU) NO 1077/2011 


Article 38 


Regulation (EU) No 1077/2011 is amondod as follows: 


(1) Article 5 is rcplaccd by the following: 


=Article 5 


In rolation to Eurodac, the Agoncy shall porfonn: 


(a) the tasks confcrrcd on it by Regulation (EU) No 603/2013 of the Europcan 
Parliamont and of the Council of 26 Juno 2013 on the establishment of 
'Eurodac' for the comparison of fingcrprints for the cffcctivc application of 
Fiogulation (EU) No 601/2013 cstablishing the criteria and mochanisms for 
dctcrmining the Member State responsible for cxamining an application for 
international protoction lodgod in ono of the Momber Statos by a third country 
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"3. Europol and Eurojust may cach appoint a rcprcscntativc to the SIS II Advis ory 
Group. Europol may also appoint a roprosontativo to the VIS and Eurodac Advisory 
Groups.".» 

CHAPTERIX 

FIN AL PR O VISIONS 


Article M 41 

Costs 

1. The costs incurred in connection with the establishment and operation of the Central 
System and the Communication Infrastructure shall be bome by the general budget of the 
European Union. 

2. The costs incurred by national access points and the costs for connection to the Central 
System shall be borne by each Member State. 

3. Each Member State and Europol shall set up and maintain at their expense the technical 
infrastructure necessary to implement this Regulation, and shall be responsible for bearing its 
costs resulting from requests for comparison with Eurodac data for the purposes laid down in 
Article lQd ltcT 


Article 441 42 

Annual report: monitoring and evaluation 

1. The Agcs ey 15> eu-LISA <3 shall submit to the European Parliament, the Council, the 
Commission and the European Data Protection Supervisor an annual report on the activities 
of the Central System, including on its technical functioning and security. The annual report 
shall include information on the management and performance of Eurodac against pre-defined 
quantitative indicators for the objectives referred to in paragraph 2. 

2. The Agcncy 1E> eu-LISA <3 shall ensure that procedures are in place to monitor the 
functioning of the Central System against objectives relating to output, cost-effectiveness and 
quality of service. 

3. For the purposes of technical maintenance, reporting and statistics, the Agcn ey E> eu- 
LISA <3 shall have access to the necessary infonnation relating to the processing operations 
perfonned in the Central System. 


-0- new 

4. By [2020] eu-LISA shall conduct a study on the technical feasibility of adding facial 
recognition software to the Central System for the purposes of comparing facial images. The 
study shall evaluate the reliability and accuracy of the results produced from facial 
recognition software for the purposes of EURODAC and shall make any necessary 
recommendations prior to the introduction of the facial recognition technology to the Central 
System. 
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* 603/2013 (adapted) 

■=> new 

45 . By 20 July 2018 ■=>[...]<=' and every four years thereafter, the Commission shall produce 
an overall evaluation of Eurodac, examining the results achieved against objectives and the 
impact on fundamental rights, including whether law enforcement access has led to indirect 
discrimination against persons covered by this Regulation, and assessing the continuing 
validity of the underlying rationale and any implications for future operations, and shall make 
any necessary recommendations. The Commission shall transmit the evaluation to the 
European Parliament and the Council. 

76. Member States shall provide the Agoncy E> eu-LISA <3 and the Commission with the 
infonnation necessary to draft the annual report referred to in paragraph 1. 

67 . The Agen ey E> eu-LISA <3 , Member States and Europol shall provide the Commission 
with the infonnation necessary to draft the overall evaluation provided for in paragraph 4 5. 
This infonnation shall not jeopardise working methods or include infonnation that reveals 
sources, staff members or investigations of the designated authorities. 

78 . While respecting the provisions of national law on the publication of sensitive 
infonnation, each Member State and Europol shall prepare annual reports on the effectiveness 
of the comparison of fingcrprint data with Eurodac data for law enforcement purposes, 
containing infonnation and statistics on: 

the exact purpose of the comparison, including the type of terrorist offence or serious 
criminal offence, 

grounds given for reasonable suspicion, 

the reasonable grounds given not to conduct comparison with other Member States 
under Decision 2008/615/JHA, in accordance with Article ^ 21(1) of this 
Regulation, 

- number of requests for comparison, 

the number and type of cases which have ended in successful identifications, and 

the need and use made of the exceptional case of urgency, including those cases 
where that urgency was not accepted by the ex post verification carried out by the 
verifying authority. 

Member States' and Europol annual reports shall be transmitted to the Commission by 30 June 
of the subsequent year. 

8-9 . On the basis of Member States and Europol annual reports provided for in paragraph 7 8 
and in addition to the overall evaluation provided for in paragraph 4 5, the Commission shall 
compile an annual report on law enforcement access to Eurodac and shall transmit it to the 
European Parliament, the Council and the European Data Protection Supervisor. 

Article ö 43 

Penalties 

Member States shall take the necessary measures to ensure that any processing of data entered 
in the Central System contrary to the purposes of Eurodac as laid down in Article 1 is 
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punishable by penalties, including administrative and/or criminal penalties in accordance with 
national law, that are effective, proportionate and dissuasive. 

Article 44 

Territorial scope 

The provisions of this Regulation shall not be applicable to any territory to which [Regulation 
(EU) No 604/2013 does not apply]. 


Article 4^ 45 

Notification of designated authorities and verifying authorities 

1. By O [...] O 20 Octobcr 2013 , each Member State shall notify the Commission of its 
designated authorities, of the operating units referred to in Article § 6(3) and of its verifying 
authority, and shall notify without delay any amendment thereto. 

2. By O [,..]0 30= Octobcr 2013 , Europol shall notify the Commission of its designated 
authority, of its verifying authority and of the National Access Point which it has designated, 
and shall notify without delay any amendment thereto. 

3. The Commission shall publish the infonnation referred to in paragraphs 1 and 2 in the 
Official Journal of the European Union on an annual basis and via an electronic publication 
that shall be available online and updated without delay. 

Article 44 


Data blockod in the Central System in accordance with Article 12 of Fiogulation (EC) 
No 2725/2000 shall be unblockcd and markcd in accordance with Article 18(1) of th is 
Regulation on 20 July 2015. 


Article ^ 46 

Repeal 

Regulation (EC) No 2725/2000 and Rugulation (EC) No 107/2002 are E> (EU) No 603/2013 
is <3 repealed with effect from 20 July 2015 0[...]0. 

References to the repealed Regulations shall be construed as references to this Regulation and 
shall be read in accordance with the correlation table in the Annex ffi. 

Article 44 4Z 

Entry into force and applicability 

This Regulation shall enter into force on the twentieth day following that of its publication in 
the Official Journal of the European Union. 

This Regulation shall apply from 20 July 2015 O [...] <=• . 
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-O- new 

Articles 2(2), 32, 32 and, for the purposes referred to in Article l(l)(a) and (b), Articles 28(4), 
30 and 37 shall apply from the date referred to in Article 91(2) ofRegulation (EU) [.../2016]. 
Until this date Articles 2(2), 27(4), 29, 30 and 35 ofRegulation 603/2013 shall apply. 

Articles 2(4), 35, and for the purposes referred to in Article l(l)(c), Article 28(4), 30, 37 and 
40 shall apply from the date referred to in Article 62(1) of Directive [2016/ .../EU]. Until this 
date Articles 2(4), 27(4), 29, 33, 35 and 37 ofRegulation 603/2013 shall apply. 

Comparisons of facial images with the use of facial recognition software as set out in Articles 
15 and 16 of this Regulation shall apply from the date upon which the facial recognition 
technology has been introduced into the Central System. Facial recognition software shall be 
introduced into the Central System [two years from the date of entry into force of this 
Regulation]. Until that day, facial images shall be stored in the Central System as part of the 
data-subjecfs data sets and transmitted to a Member State following the comparison of 
fmgerprints where there is a hit result. 


* 603/2013 (adapted) 

■=> new 

Member States shall notify the Commission and the Agoncy E> eu-LISA <3 as soon as they 
have made the technical arrangements to transmit data to the Central System E> under 
Articles XX-XX <S1 , and in any ovont no later than 20 July 2015 ■=> [...] <p . 


This Regulation shall be binding in its entirety and directly applicable in the Member States in 
accordance with the Treaties. 

Done at Brussels, 


For the European Parliament For the Council 

The President The President 
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Regulation (EU) No 603/2013 

This Regulation 

Article 1(1) 

Article l(l)(a) and (b) 

Article 1(2) 

Article l(l)(c) 

Article 1(3) 

- 

- 

Article 1(3) 

- 

Article 2(1) to (4) 

Article 2(1), introductory wording 

Article 3(1), introductory wording 

Article 2(1 )(a) and (b) 

Article 3(1 )(a) and (b) 
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Article 3(1 )(c) 

Article 2(1 )(c) 

Article 3(l)(d) 
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Article 3(5) 
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LEGISLATIVE FINANCIAL STATEMENT 


1. FRAMEWORK OF THE PROPOSAL/INITIATIVE 

1.1. Title of the proposal/initiative 


Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE 
COUNCIL on the establishment of Eurodac for the comparison of fingerprints for the 
effective application of [Regulation (EU) No 604/2013] establishing the criteria and 
mechanisms for determining the Member State responsible for examining an application 
for international protection lodged in one of the Member States by a third-country national 
or a stateless person, for identifying an irregular third-country national or stateless person 
and on requests for the comparison with Eurodac data by Member States' law enforcement 
authorities and Europol for law enforcement purposes (recast) _ 

1.2. Policy area(s) concerned in the ABM/ABB structure 46 

Policy area: Migration and Home Affairs (title 18) 

Activity: Asylum and Migration 

1.3. Nature of the proposal/initiative 

□ The proposal/initiative relates to a new action 

□ The proposal/initiative relates to a new action following a pilot project/preparatory 
action 47 

13 The proposal/initiative relates to the extension of an existing action 

□ The proposal/initiative relates to an action redirected towards a new action 

1.4. Objective(s) 

1.4.1. The Commission's multiannual strategie objective(s) targeted by the proposal/initiative 

In the European Agenda on Migration (COM(2015)240 final) the Commission announced 
that it will have to evaluate the Dublin system and detennine whether a revision of the 
legal parameters of Dublin will be needed to achieve a fairer distribution of asylum seekers 
in Europe. The Commission also proposed to look into the possibility of adding additional 
biometric identi fiers to EURODAC, such a facial images and the use of facial recognition 
software. 

The refugee crisis has exposed significant structural weaknesses and shortcomings in the 
design and implementation of European asylum and migration policy, including the Dublin 
and EURODAC Systems, which prompted calls for reform. 

On 6 April in its Communication "Towards a reform of the Common European Asylum 
System and enhancing legal avenues to Europe" (COM(2016) 197 final) the Commission 
considered it a priority to bring forward a reform of the Dublin Regulation and establish a 
sustainable and fair system for determining the Member State responsible for asylum 
seekers ensuring a high degree of solidarity and a fair sharing of responsibility between 
Member States by proposing a corrective allocation mechanism. 

As part of this, the Commission considered that EURODAC should be reinforced to reflect 
changes to the Dublin mechanism and to make sure that it continues to provide the 
fingerprint evidence it needs to function. It was also considered that EURODAC could 


ABM: activity-based management; ABB: activity-based budgeting. 
As referred to in Article 54(2)(a) or (b) of the Financial Regulation. 
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contribute to the fight against irregular migration by storing tïngerprint data under all 
categories and allowing comparisons to be made with all stored data for that purpose. 


1.4.2. Specific objective(s) and ABM/ABB activity(ïes) concerned 

DG HOME AMP Specific objective No 1: To strengthen and develop all aspects of the 
Coinmon European Asylum System, including its external dimension. 

ABM/ABB activity(ies) concerned: Activity 18 03: Asylum and Migration. 

Specific objective No 1: Eurodac functional system evolution 

Specific objective No 2: Eurodac database capacity upgrade 
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1.4.3. Expected result(s) and impact 

Specify the effects which the proposal/initiative should have on the beneficiaries/gronps targeted. 

The proposal will aim to enhance the Identification of irregular third-country nationals 
within the EU as well as to ensure the effective implementation of the revised Dublin 
Regulation by providing fingerprint evidence to determine the Member State responsible 
for examining an application of international protection. 

This proposal aims to assist Member States to ensure that an applicant for international 
protection will have their application examined by a single Member State and will reduce 
the scope of abuse of the asylum system by deterring “asylum shopping” within the EU. 

Member States will also benefit from being able to identify irregular third-country 
nationals illegally staying in the EU by storing their personal data and indicating the first 
country through which they entered or where they may also been staying illegally. The 
Information stored at EU level will in turn assist a Member State to re-document a third- 
country national with a view to returning them to their country of origin or a third-country 
to which they will be readmitted. 

Many applicants for international protection and third-country nationals arriving 
irregularly to the European Union travel with families and in many cases with very young 
children. Being able to identify these children with the help of fingerprints and facial 
images will help to identify them in cases where they are separated from their families by 
allowing a Member State to follow up a line of inquiry where a fingerprint match indicates 
that they were present in another Member State. It would also strengthen the protection of 
unaccompanied minors who do not always formally seek international protection and who 
abscond from care institutions or child social services to which their care has been 
assigned. Under the current legal and technical framework their identify cannot be 
established. Thus the EURODAC system could be used to register children from third- 
countries where they are found undocumented within the EU to help keep track of them 
and prevent them from ending up in scenarios of exploitation. 

1.4.4. Indicators of results and impact 

Specify the indicators for monitoring implementation of the proposal/initiative. 

Purina the upgrading of the Central System 

After the approval of the draft proposal and the adoption of the technical specifications the 
recast EURODAC Central System will be upgraded in terms of capacity and througput for 
transmission from the Member States’ National Access Points. eu-LISA will coordinate the 
project management of upgrading the Central System and the national Systems at EU level 
and the integration of the National Uniform Interface (NUI) carried out by Member States 
at national level. 

Specific Objective: Ready for operations when the amended Dublin Regulation will go 
live. 

Indicator: In order to go live, eu-LISA has notified the successful completion of a 
comprehensive test of the EURODAC Central System which shall be conducted by the 
Agency together with the Member States. 

Once the new Central System is operational 

Once the EURODAC system is operational eu-LISA shall ensure that Systems are in place 
to monitor the functioning of the system against objectives. At the end of each year eu- 
LISA should submit to the European Parliament, the Council and the Commission a report 
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on the activities of the Central System, including on its technical functioning and security. 
The annual report shall include Information on the management and performance of 
Eurodac against pre-defmed quantitative indicators for its objectives. 

By 2020, eu-LISA should conduct a study on the technical feasibility of adding facial 
recognition software to the Central System that ensures reliable and accurate results 
following a comparison of facial image data. 

By 20 July 2018 and every four years thereafter, the Commission shall produce an overall 
evaluation of Eurodac, examining the results achieved against objectives and the impact on 
fundamental rights, including whether law enforcement access has led to indirect 
discrimination against persons covered by this Regulation, and assessing the continuing 
validity of the underlying rationale and any implications for future operations, and shall 
make any necessary recommendations. The Commission shall transmit the evaluation to 
the European Parliament and the Council. 

Each Member State and Europol shall prepare annual reports on the effectiveness of the 
comparison of fingerprint data with EURODAC data for law enforcement purposes, 
containing statistics on the number of requests made and hits received. 


1.5. Grounds for the proposal/initiative 

1.5.1. Requirement(s) to be met in the short or long term 

(1) Detennining the Member State responsible under the amended Dublin Regulation 
proposal. 

(2) Control the identity of irregular third-country nationals to and within the EU for the 
purposes of re-documentation and return and identifying vulnerable third-country nationals 
such as children who often fall victim to smuggling. 

(3) The flght against international criminality, terrorism and other security threats is 
reinforced. 


1.5.2. Added value of EU involvement 

No Member State alone is able to cope on its own with irregular immigration or deal with 
all the asylum applications made within the EU. As has been witnessed in the EU for many 
years, a person may gain entry to the EU via the external borders, but not declare 
themselves at a designated border Crossing point. This has been the case in particular in 
2014-2015 where over one million irregular migrants arrived to the EU via the Central and 
Southern Mediterranean routes. Similarly, 2015 witnessed onward movements from those 
countries situated at the external borders to other Member States. The monitoring of 
compliance with EU rules and procedures such as the Dublin procedure therefore cannot 
be done by Member States acting alone. In an area without internal borders, action against 
irregular immigration should be undertaken in coinmon. Considering all this, the EU is 
better placed than Member States to take the appropriate measures. 

The use of the three existing EU large-scale IT Systems (SIS, VIS and Eurodac) brings 
bene fits to border management. Better information on cross border movements of third 
country nationals at EU level would help establish a factual basis to develop and adapt the 
EU migration policy. Therefore, an amendment of the EURODAC Regulation is also 
required in order to add an additional purpose thereto, namely allow access for the purpose 
of controlling illegal migration to and secondary movements of irregular migrants within 
the EU. This objective cannot be sufficiently achieved by the Member States on their own, 
since such amendment can only be proposed by the Commission. 
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1.5.3. Lessons learned from similar experiences in the past 


The main lessons learnt from upgrading the Central System following the adoption of the 
flrst recast EURODAC Regulation 48 was the importance of early project management by 
Member States and ensuring that the project of upgrading the national connection was 
managed against milestones. Even though a rigid project management Schedule was set by 
eu-LISA for both upgrading the Central System and Member States national connections, a 
number of Member States failed or risked connecting to the Central System by 20 July 
2015 (two years after adoption of the Regulation). 

In the Lessons Leamt workshop following the upgrading of the Central System in 2015, 
Member States also flagged that a roll-out phase was needed for the next upgrade of the 
Central System to ensure that all Member States could manage to connect to the Central 
System on time. 

Alternative Solutions were found for those Member States that were late to connect to the 
Central System in 2015. These included eu-LISA lending a National Access Point/ 
Fingerprint Image Transmission (NAP/FIT) solution to one Member State that was used 
for testing simulations by the Agency, because the Member State in question had failed to 
secure the necessary funding to begin their procurement procedure shortly after the 
adoption of the EURODAC Regulation. Two other Member States had to resort to using an 
‘in-house’ solution for their connection before installing their procured NAP/FIT Solutions. 

The use of a Framework Contract to provide functionalities and provision of maintenance 
services for the EURODAC System was established by eu-LISA and an external 
Contractor. Many Member States used this framework contract to procure a standardised 
NAP/FIT solution, which was deemed to have made savings and avoided the need for 
national procurement procedures. A framework contract of this sort should be considered 
again for the future upgrade. 


1.5.4. Compatibility andpossible synergy with other appropriate instruments 

This proposal should be seen as part of the continuous development of the Dublin 
Regulation 49 , the Commission’s Communication "Towards a reform of the Common 
European Asylum System and enhancing legal avenues to Europe" 50 , and in particular the 
Commission’s Communication on Stronger and Smarter Information Systems for Borders 
and Security 51 , as well as in conjunction with the ISF borders 52 , as part of the MFF and the 
establishing Regulation of eu-LISA''. 


OJL 180, 29.6.2013, p.1 

Regulation (Eu) No. 604/2013 of the European Parliament and of the Council of 26 June 2013 establishing the 
criteria and mechanisms for determining the Member State responsible for examining an application for 
international protection lodged in one of the Member States by a third-country national or a stateless person 
(recast). OJL 180, 29.6.2013, p31. 

COM(2016) 197 final. 

COM(2016) 205 final 

Regulation (EU) No 515/2014 of the European Parliament and of the Council of 16 April 2014 establishing, as 
part of the Internal Security Fund, the instrument for Financial support for external borders and visa and 
repealing Decision No 574/2007/EC, OJ LI50, 20.5.2014, p.143 

Regulation (EU) No 1077/2011 of the European Parliament and of the Council of 25 October 2011 
establishing a European Agency for the operational management of large-scale IT systems in the area of 
freedom, security and justice. Article 1.3 "The Agency may also be made responsible for the preparation, 
development and operational management of large-scale IT systems in the area of freedom, security and justice 
other than those referred to in paragraph 2, only if so provided by relevant legislative instruments...", OJ L 
286, 1.11.2011, p. 1-17 
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Within the Commission DG HOME is the Directorate General responsible for the 
establishment of EURODAC. 
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1.6. Duration and finandal impact 

□ Proposal/initiative of limited duration 

- □ Proposal/initiative in effect from [DD/MMJYYYY to [DD/MMJYYYY 

- □ Financial impact from YYYY to YYYY 
0 Proposal/initiative of unlimited duration 

- Implementation with a start-up period from 2017 to 2020, 

- followed by full-scale operation. 

1.7. Management mode(s) planned 54 

0 Direct management by the Commission through 

- (Ei by its departments, including by its staff in the Union delegations; 

- □ executive agencies 

□ Shared management with the Member States 

[Ei Indirect management by entrusting budget implementation tasks to: 

□ international organisations and their agencies (to be specilied); 

□the EIB and the European Investment Fund; 

IE] bodies referred to in Articles 208 and 209; 

□ public law bodies; 

□ bodies governed by private law with a public service mission to the extent that they 
provide adequate Financial guarantees; 

□ bodies governed by the private law of a Member State that are entrusted with the 
implementation of a public-private partnership and that provide adequate Financial 
guarantees; 

□ persons entrusted with the implementation of specific actions in the CFSP pursuant to 
Title V of the TEU, and identified in the relevant basic act. 

Comments 

The Commission will be responsible for the overall management of the action and eu-LISA will be 
responsible for the development, operation and maintenance of the System. 


Details of management modes and references to the Financial Regulation may be found on the BudgWeb site: 
https://myintracomm.ec.eiiropa.eu/biidgweb/EN/man/biidgmanag/Pages/biidgmanag.aspx . 
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2. MANAGEMENT MEASURES 

2.1. Monitoring and reporting rules 

Specify frequency and conditions. 

The rules on monitoring and evaluation of the Eurodac System are foreseen in Article 40 of the 
proposal: 

Annual report: monitoring and evaluation 

1. eu-LISA shall submit to the European Parliament, the Council, the Commission and the 
European Data Protection Supervisor an annual report on the activities of the Central System, 
including on its technical functioning and security. The annual report shall include infonnation 
on the management and performance of Eurodac against pre-defined quantitative indicators 
for the objectives referred to in paragraph 2. 

2. eu-LISA shall ensure that procedures are in place to monitor the functioning of the Central 
System against objectives relating to output, cost-effectiveness and quality of service. 

3. For the purposes of technical maintenance, reporting and statistics, eu-LISA shall have 
access to the necessary information relating to the processing operations performed in the 
Central System. 

3a. By [2020] eu-LISA shall conduct a study on the technical feasibility of adding facial 
recognition software to the Central System for the purposes of comparing facial images. The 
study shall evaluate the reliability and accuracy of the results produced from facial recognition 
software for the purposes of EURODAC and shall make any necessary recommendations prior 
to the introduction of the facial recognition technology to the Central System. 

4. By XX/XX/XX and every four years thereafter, the Commission shall produce an overall 
evaluation of Eurodac, examining the results achieved against objectives and the impact on 
fundamental rights, including whether law enforcement access has led to indirect 
discrimination against persons covered by this Regulation, and assessing the continuing 
validity of the underlying rationale and any implications for future operations, and shall make 
any necessary recommendations. The Commission shall transmit the evaluation to the 
European Parliament and the Council. 

5. Member States shall provide eu-LISA and the Commission with the information necessary 
to draft the annual report referred to in paragraph 1. 

6. eu-LISA, Member States and Europol shall provide the Commission with the information 
necessary to draft the overall evaluation provided for in paragraph 4. This infonnation shall 
not jeopardise working methods or include information that reveals sources, staff members or 
investigations of the designated authorities. 

7. While respecting the provisions of national law on the publication of sensitive information, 
each Member State and Europol shall prepare annual reports on the effectiveness of the 
comparison of fingcrprint data with Eurodac data for law enforcement purposes, containing 
infonnation and statistics on: 

— the exact purpose of the comparison, including the type of terrorist offence or serious 
criminal offence, 

— grounds given for reasonable suspicion, 
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— the reasonable grounds given not to conduct comparison with other Member States 
under Decision 2008/615/JHA, in accordance with Article 20(1) of this Regulation, 

— number of requests for comparison, 

— the number and type of cases which have ended in successful identifications, and 

— the need and use made of the exceptional case of urgency, including those cases where 
that urgency was not accepted by the ex post vcrilication carried out by the verifying 
authority. 

Member States' and Europol annual reports shall be transmitted to the Commission by 30 June 
of the subsequent year. 

8. On the basis of Member States and Europol annual reports provided for in paragraph 7 and 
in addition to the overall evaluation provided for in paragraph 4, the Commission shall 
compile an annual report on law enforcement access to Eurodac and shall transmit it to the 
European Parliament, the Council and the European Data Protection Supervisor. 


2.2. Management and control system 

2.2.1. Risk(s) identified 

The following risks are identified: 

1) Difficulties for eu-LISA to manage the development of this system in parallel to 
development related to other more complicated Systems (Entry-Exit system, AFIS for SIS II, 
VIS, ...) taking place within the same time period. 

2) The upgrade Eurodac needs to be integrated with the national IT Systems which need to be 
fully aligned with central requirements. The discussions with Member States to ensure 
unifonnity in the usage of the system may introducé delays in the development. 


2.2.2. Control method(s) envisaged 

The Agency’s accounts will be submitted for the approval of the Court of Auditors, and 
subject to the discharge procedure. The Commission’s Intemal Audit Service will carry out 
audits in cooperation with the Agency's internal auditor. 


2.3. Measures to prevent fraud and irregularities 

Specify existing or envisaged prevention and protection measures. 

The measures foreseen to combat fraud are laid down in Article 35 of Regulation (EU) 
1077/2011 which provides as follows: 

1. In order to combat fraud, corruption and other unlawful activities, Regulation (EC) No 
1073/1999 shall apply. 

2. The Agency shall accede to the Interinstitutional Agreement concerning intemal 
investigations by the European Anti-Fraud Office (OLAF) and shall issue, without delay, the 
appropriate provisions applicable to all the employees of the Agency. 
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3. The decisions concerning funding and the implementing agreements and Instruments 
resulting from them shall explicitly stipulate that the Court of Auditors and OLAF may carry 
out, if necessary, on-the-spot checks among the recipients of the Agency's funding and the 
agents responsible for allocating it. 

In accordance with this provision, the decision of the Management Board of the European 
Agency for the operational management of large-scale IT Systems in the area of freedom, 
security and justice concerning the terms and conditions for internal investigation sin relation 
to the prevention of fraud, corruption and any illegal activity detrimental to the Union's 
interests was adopted on 28 June 2012. 

DG HOME’s fraud prevention and detection strategy will apply. 
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3. ESTIMATED FINANCIAL IMPACT OF THE PROPOSAL/INITIATIVE 

3.1. Heading(s) of the multiannual financial framework and expenditure budget line(s) 
affected 


• Existing budget lines 


In order of multiannual financial framework headings and budget lines. 


Heading of 
multiannual 
financial 
framework 

Budget line 

Type of 
expenditure 

Contribution 

Fleading 3 - Security and Citizenship 

Diff./Non- 

diff. 55 

from 

EFTA 

countries 

56 

from 

candidate 

countries 57 

from third 
countries 

within the meaning 
of Article 21(2)(b) 
of the Financial 
Regulation 

3 

18.0303 - European fingerprint database (Eurodac) 

Diff. 

NO 

NO 

NO 

NO 

3 

18.0207 - European Agnecy for the operational 
management of large-scale IT systems in the area 
of freedom, security and justice (eu-LISA) 

Diff. 

NO 

NO 

YES* 

NO 


* eu-LISA receives contributions from the countries associated with 


the Schengen Agreement (NO, IS, 


CH, LI) 


Diff. = Differentiated appropriations / Non-diff. = Non-differentiated appropriations. 
EFTA: European Free Trade Association. 

Candidate countries and, where applicable, potential candidates from the Western Balkans. 
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3.2. 

3.2.1. 


Estimated impact on expenditure 

Summary of estimated impact on expenditure 


EUR million (to three decimal places) 


Heading of multiannual financial 
framework 


3 


Seciirity and Citizenship 


eu-LISA 



Year 

2017 58 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as 
necessary to show the duration 
of the impact (see point 1.6) 

TOTAL 

Title 1: Staff expenditure 

Commitments 

(1) 

0,268 

0,268 

0,268 

0,268 




1,072 

Payments 

(2) 

0,268 

0,268 

0,268 

0,268 




1,072 

Title 2: Infrastmcture and operating 
expenditure 

Commitments 

(la) 

0 

0 

0 

0 




0 

Payments 

(2a) 

0 

0 

0 

0 




0 

Title 3: Operational expenditure * 

Commitments 

(3a) 

11,330 

11,870 

5,600 

0 




28,800 


Payments 

(3b) 

7,931 

8,309 

3,920 

8,640 




28,800 

TOTAL appropriations 
for eu-LISA 

Commitments 

=l+la 

+3a 

11,598 

12,138 

5,868 

0,268 




29,872 

Payments 

=2+2a 

+3b 

8,199 

8,577 

4,188 

8,908 




29,872 


* The Impact assessment performed by eu-LISA foresees a continuous increase of the traffic rates as during the last months of 2015 before the 
border close along the west Balkan route. 

* The potential costs for DubliNet upgrades and System operation are included in the Title 3 total. 


Year N is the year in which implementation of the proposal/initiative starts. 
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Heading of multiannual financial 
framework 


5 


‘Administrative expenditure’ 


EUR million (to three decimal places) 



Year 

2017 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as 
necessary to show the duration 
of the impact (see point 1.6) 

TOTAL 

DG: Migration and Home Affairs 


• Human Resources 

0,402 

0,402 

0,402 

0,402 




1,608 

• Other administrative expenditure 









TOTAL DG Migration and Home Affairs 

Appropriations 

0,402 

0,402 

0,402 

0,402 




1,608 


TOTAL appropriations 
under HEADING 5 

(Total commitments = 
Total payments) 

0,402 

0,402 

0,402 

0,402 




1,608 

of the multiannual financial framework 










EUR million (to three decimal places) 



Year 

2017 59 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as 
necessary to show the duration 
of the impact (see point 1.6) 

TOTAL 

TOTAL appropriations 
under HEADINGS 1 to 5 

of the multiannual financial framework 

Commitments 

12,000 

12,540 

6,270 

0,670 




31,480 

Payments 

8,601 

8,979 

4,590 

9,310 




31,480 


There is no Europol related costs since Europol accesses Eurodac via the Dutch National Interface to Eurodac. 


Year N is the year in which implementation of the proposal/initiative starts. 
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3.2.2. Estimated impact on eu-LISA 's appropriations 

- □ The proposal/initiative does not require the use of operational appropriations 

- 0 The proposal/initiative requires the use of operational appropriations, as explained below: 

Commitment appropriations in EUR million (to three decimal places) 


Indicate 

objectives 

and 

outputs 

■0- 



Year 

2017 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as necessary to show the 
duration of the impact (see point 1.6) 

TOTAL 

OUTPUTS 

Type 60 

Average 

cost 

O 

Z 

Cost 

O 

z 

Cost 

O 

Z 

Cost 

O 

Z 

Cost 

O 

z 

Cost 

O 

Z 

Cost 

O 

z 

Cost 

Total 

No 

Total 

cost 

SPECIFIC OBJECTIVE No l 61 
Eurodac functional system evolution 


- Output 

Contractor * 


0,130 


0,670 


0 


0 








0,800 

Subtotal for specific objective No 1 


0,130 


0,670 


0 


0 








0,800 

SPECIFIC OBJECTIVE No 2 
Eurodac database capacity upgrade 


- Output 

Hardware, Software ** 


11,200 


11,200 


5,600 


0 








28,000 

Subtotal for specific objective No 2 


11,200 


11,200 


5,600 


0 








28,000 

TOTAL COST 


11,330 


11,870 


5,600 


0 








28,800 


* All contractual costs for the functional updates are split between the first 2 years with the biggest part of the budget in the 2 nd year 
(following acceptance) 

** Capacity payments is split within the 3 years as 40%, 40%, 20% 

Outputs are products and services to be supplied (e.g.: number of student exchanges fmanced, number of km of roads built, etc.). 

As described inpoint 1.4.2. ‘Specific objective(s)...’ 


EN 


102 


EN 


















3.2.3. Estimated impact on eu-LISA 's human resources 
3.2.3.1. Summary 

- □ The proposal/initiative does not require the use of appropriations of an 
administrative nature 


- 0 The proposal/initiative requires the use of appropriations of an administrative 
nature, as explained below: 

EUR million (to three decimal places) 



Year 

2017 62 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as necessary to 
show the duration of the impact (see 
point 1.6) 

TOTAL 


Officials (AD Grades) 

0,268 

0,268 

0,268 

0,268 




1,072 

Officials (AST grades) 









Contract staff 









Temporary staff 









Seconded National Experts 










TOTAL 

0,268 

0,268 

0,268 

0,268 




1,072 


Estimated impact on the staff (additional FTE) - establishment plan of eu-LISA 


Posts (establishment plan) 

2017 

2018 

2019 

2020 

Baseline - Communication 63 

115 

113 

113 

113 

Additional posts 

2 

2 

2 

2 

Additional posts EES 

14 

14 

14 

14 

Total 

131 

129 

129 

129 


Year 2017 is the year in which implementation of the proposal/initiative starts. 

COM(2013) 519 final: Communication from the Commission to the European Parliament and the 
Council - Programming of human and fmancial resources for decentralised agencies 2014-2020. 
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Recruitment is planned for January 2017. All staff must be available as of early 2017 in order 
to allow starting the development in due time with a view of ensuring an entry into operations 
of Eurodac in 2017. The 2 new Temporary Agents (TAs) are needed to cover needs both for 
the project implementation as well as for operational support and maintenance after 
deployment to production. These resources will be used: 

• To support the project implementation as project team members, including activities 
as: the definition of requirements and technical specifications, cooperation and 
support to MS during the implementation, updates of the Interface Control Document 
(ICD), the follow-up of the contractual deliveries, project testing activities (including 
MS test coordination), documentation delivery and updates etc. 

• To support transition activities for putting the System into operations in cooperation 
with the contractor (releases follow-up, operational process updates, trainings 
(including MS training activities) etc. 

• To support the longer tenn activities, definition of specifications, contractual 
preparations in case there is reengineering of the System (e.g. due to Image 
recognition) or in case the new Eurodac Maintenance in Working Order (MWO) 
contract will need to be amended to cover additional changes (from technical and 
budgetary perspective) 

• To enforce the second level support following Entry into Operation (EiO), during 
continuous maintenance and operations. 

It has to be noted that the two new resources (FTE TA) will act on top of the internal team 
capabilities which will be as well utilised for the project/contractual and financial follow-up/ 
operational activities. The use of TAs will provide adequate duration and continuity of the 
contracts to ensure business continuity and use of the same specialized people for operational 
support activities after the project conclusion. On top the operational support activities 
require access to Production environment that cannot be assigned to contractors or external 
staff. 


3.2.3.2. Estimated requirements of human resources for the parent DG 

- □ The proposal/initiative does not require the use of human resources. 

- S The proposal/initiative requires the use of human resources, as explained 
below: 


Estimate to be expressed infull amounts (or at most to one decimal place) 



Year 

2017 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as 
necessary to show the 
duration of the impact (see 
point 1.6) 

TOTAL 

• Establishment plan posts (officials 
and temporary staff) 









18 01 01 01 (Headquarters 
and Commission’s 
Representation Offices) 

0,402 

0,402 

0,402 

0,402 




1,608 

XX 01 01 02 (Delegations) 
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XX 01 05 01 (Indirect 
research) 









10 01 05 01 (Direct research) 


















• External staff (in Full Time 
Equivalent unit: FTE) 64 









XX 01 02 01 (AC, END, 

INT from the ‘global 
envelope’) 









XX 01 02 02 (AC, AL, 

END, INT and JED in the 
Delegations) 









XX01 

04 j/ 5 

at 

Headquarters 66 









- in Delegations 









XX 01 05 02 (AC, END, 

INT - Indirect research) 









10 01 05 02 (AC, END, INT 
- Direct research) 









Other budget lines (specify) 









TOTAL 

0,402 

0,402 

0,402 

0,402 




1,608 


18 is the policy area or budget title concerned. 


The human resources required will be met by staff from the DG who are already assigned to 
management of the action and/or have been redeployed within the DG, together if necessary with any 
additional allocation which may be granted to the managing DG under the annual allocation procedure 
and in the light of budgetary constraints. 


Description of tasks to be carried out: 


Officials and temporary staff 

Various tasks in relation to Eurodac, e.g. in the context of Commission opinion on the 
annual work programme and monitoring of its implementation, supervision of the 
preparation of the Agency's budget and monitoring of its implementation, assisting the 
Agency in developing its activities in line with EU policies including by participating 
in experts meetings, etc. 

External staff 



Description of the calculation of cost for FTE units should be included in the Annex V, 
section 3. 


AC = Contract Staff; AL = Local Staff; END = Seconded National Expert; INT = agency staff; JED = 
Junior Experts in Delegations. 

Sub-ceiling for external staff covered by operational appropriations (former ‘BA’ lines). 

Mainly for the Structural Funds, the European Agricultural Fund for Rural Development (EAFRD) and 
the European Fisheries Fund (EFF). 
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3.2.4. Compatibüity with the current multiannualfinancial framework 

- S The proposal/initiative is compatible the current multiannual financial 
framework. □ The proposal/initiative will entail reprogramming of the 
relevant heading in the multiannual financial framework. 


- □ The proposal/initiative requires application of the flexibility instrument or 

f\l 

revision of the multiannual financial framework . 


3.2.5. Third-party contributions 

- S The proposal/initiative does not provide for co-financing by third parties. 

- □ The proposal/initiative provides for the co-financing estimated below: 


EUR million (to three decimal places) 



Year 

2017 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as 
necessary to show the duration 
of the impact (see point 1.6) 

Total 

Specify the co-financing 
body 









TOTAL appropriations 
co-financed 










See Articles 11 and 17 of Council Regulation (EU, Euratom) No 1311/2013 laying down the 
multiannual financial framework for the years 2014-2020. 
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3.3. Estimated impact on revenue 

- □ The proposal/initiative has no linancial impact on revenue. 

- 0 The proposal/initiative has the following financial impact: 

□ on own resources 

1X1 on miscellaneous revenue 


EUR million (to three decimal places) 


Budget revenue line: 

Appropriation 
s available for 
the current 
financial year 

Impact of the proposal/initiative 6S 

Year 

2017 

Year 

2018 

Year 

2019 

Year 

2020 

Enter as many years as necessary to show 
the duration of the impact (see point 1.6) 

Article. 


0,492 

0,516 

0,243 

0,536 



For miscellaneous ‘assigned’ revenue, specify the budget expenditure line(s) affected. 


Specify the method for calculating the impact on revenue. 

The budget shall include a contribution frorn countries associated with the Eurodac 
related measures as laid down in the respective agreements *. The estimates provided 
are purely indicative and are based on calculations for revenues for the 
implementation of the Eurodac System frorn the States that currently contribute the 
general budget of the European Union (consumed payments) an annual sum for the 
relevant financial year, calculated in accordance with its gross domestic product as a 
percentage of the gross domestic product of all the participating States. The 
calculation is based on June 2015 figures frorn EUROSTAT which are subject to 
considerable variation depending on the economie situation of the participating 
States. 

* Agreement between the European Community and the Republic of Iceland and the Kingdom of Norway 
concerning the criteria and mechanisms for establishing the State responsible for examining a request for asylum 
lodged in a Member State or in Iceland or Norway (OJ L 93, 3.4.2001, p. 40). 

Agreement between the European Community and the Swiss Confederation concerning the criteria and 
mechanisms for establishing the State responsible for examining a request for asylum lodged in a Member State 
or in Switzerland (OJ L 53, 27.2.2008, p. 5). 

Protocol between the European Community, the Swiss Confederation and the Principality of Liechtenstein on 
the accession of the Principality of Liechtenstein to the Agreement between the European Community and the 
Swiss Confederation concerning the criteria and mechanisms for establishing the State responsible for examining 
a request for asylum lodged in a Member State or in Switzerland (OJ L 160 18.6.2011 p. 39) 

Protocol between the European Community, the Swiss Confederation and the Principality of Liechtenstein to 
the Agreement between the European Community and the Swiss Confederation concerning the criteria and 
mechanisms for establishing the State responsible for examining a request for asylum lodged in a Member State 
or in Switzerland (2006/0257 CNS, concluded on 24.10.2008, publication in OJ pending) and Protocol to the 
Agreement between the Community, Republic of Iceland and the Kingdom of Norway concerning the criteria 
and mechanisms for establishing the State responsible for examining a request for asylum lodged in a Member 
State, Iceland and Norway (OJ L 93, 3.4.2001). 


As regards traditional own resources (customs duties, sugar levies), the amounts indicated must be net 
amounts, i.e. gross amounts after deduction of 25 % for collection costs. 
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